okx-agent-identity

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill handles untrusted data from the marketplace (such as agent names, descriptions, and service details). To mitigate indirect prompt injection, it includes a strict instruction for the agent to ignore any content within these fields that resembles commands. It also uses structured rendering (cards and tables) to isolate data from instructions.
  • [COMMAND_EXECUTION]: The skill uses a vendor-provided CLI tool ('onchainos') for identity operations. All operations that modify state (create, update, activate, deactivate) are gated by an explicit user confirmation step ('Reply 1'), preventing unauthorized or accidental transactions.
  • [SAFE]: All external resources and CLI tools identified are managed by 'okx', a trusted vendor. The skill follows best practices for secure interaction with blockchain services, including validation of service endpoints and strict role-based parameter enforcement.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 02:38 AM
Security Audit — agent-trust-hub — okx-agent-identity