okx

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches specialized sub-skills and configuration from OKX's official GitHub repository (okx/onchainos-skills) during installation using npx or CLI commands.
  • [REMOTE_CODE_EXECUTION]: Instructs the user to install the onchainos binary by piping remote shell and PowerShell scripts directly from OKX's GitHub repository (install.sh and install.ps1) into the command interpreter.
  • [INDIRECT_PROMPT_INJECTION]: The skill surface includes processing external data from the blockchain and market, which could be manipulated by third parties to influence agent behavior.
  • Ingestion points: The okx-dex-market sub-skill ingests token metadata, holder cluster analysis, crypto news, and social sentiment from the web.
  • Boundary markers: None are specified in the directory instructions to delimit or neutralize instructions embedded in external data.
  • Capability inventory: The skill has access to the onchainos CLI, which can perform wallet operations, execute trades, and manage payments.
  • Sanitization: No sanitization or validation protocols are described for the ingestion of news or market sentiment data.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/okx/onchainos-skills/main/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 03:33 AM
Security Audit — agent-trust-hub — okx