Back to skill

Security audit

okx-cex-auth

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches OKX authentication setup, but it under-discloses risky credential and installation paths for a financial account tool.

Review this before installing. Prefer entering OKX API credentials only through local CLI prompts, not chat. If installing the CLI or okx-auth binary, confirm the exact package version and trust boundary, and avoid force-removing auth components unless you explicitly intend to disrupt local OKX auth.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:92
Finding

API Credentials May Be Disclosed Through the Agent Conversation

Content
View full analysis
/account/my-api`) and either provides `AK/SK/PP` to you or re-runs `okx config init` themselves. ``` ### Technical Analysis The instruction explicitly allows a user to provide the OKX API key, secret key, and passphrase (`AK/SK/PP`) directly to the Agent. These values are sensitive authentication credentials and should not be transmitted through a conversational interface. Credentials submitted this way can become part of the Agent context, conversation history, provider telemetry, debugging traces, or tool logs. The document already identifies `okx config init` as a local credential-entry mechanism, making disclosure to the Agent unnecessary. The actual permissions available to an attacker depend on the permissions assigned to the exposed API key. A read-only key may expose account, balance, position, and transaction information. A key with trading permissions may allow unauthorized orders or account-position changes. Any additional permissions granted to the key would increase the potential impact. ### Attack Path 1. A user encounters an invalid API key and follows the replacement instructions. 2. The user chooses the documented option to provide `AK/SK/PP` to the Agent. 3. The API key, secret key, and passphrase enter the conversation and Agent context. 4. The credentials may be retained in chat history, application logs, telemetry, support exports, or other intermediate systems. 5. A party or compromised component with access to those records obtains the credentials. 6. The exposed credentials are used to authenticate to OKX within the API key's configured permissions. ### Impact Assessment Successful exploitation could expose private account ...[truncated 401 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:271
Finding

Installation of an Unverified Package and Remotely Downloaded Authentication Binary

Content
View full analysis
**IMPORTANT for AI agents:** Do NOT manually check platform, CDN availability, or binary paths. Always use the CLI commands below — they handle platform detection and download internally. ### Install / Update ```bash okx auth install ``` Downloads or updates the `okx-auth` binary. Reports "up to date" if already current. Use `--json` for machine-readable output. ``` ### Technical Analysis The metadata pins the npm package to version `1.3.7`, but the documented prerequisite command installs `@okx_ai/okx-trade-cli` without a version constraint. As a result, execution of the prerequisite at a later date can install a different package version than the version reviewed by this audit. The npm package can also install or update a separate native `okx-auth` executable from unspecified CDN sources. The skill does not document an approved download-domain allowlist, expected cryptographic digest, digital-signature verification process, package integrity value, or provenance policy. It also directs Agents not to inspect CDN availability or binary paths, reducing transparency into the executable source and destination. This creates a supply-chain trust boundary in which the effective executable payload may differ after the skill itself has been reviewed. Compromise of the npm publisher account, registry package, package lifecycle scripts, binary distribution infrastructure, CDN, update manifest, or signing process could lead to ...[truncated 1784 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

text

     **DO NOT include any other field from `auth status --json` in this reply.** Specifically:
     - `expiresAt` / `ttl` refer to the short-lived access token, not the OAuth session. The CLI auto-refreshes tokens transparently; surfacing these values will mislead users into thinking their login expires soon.
     - `profile` is an internal routing field with no user value.
     - Only `site` and `scopes` are user-relevant.
     - If asked about session longevity, say "Session stays active as long as you use the CLI periodically." Do not quote a number.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description includes phrases like 'authenticate', 'authorize', 'first time setup', and 'login status', which are broad enough to overlap with many ordinary support requests. Although many examples are OKX-specific, the activation rule also says 'Also when the user asks about login status' without tighter constraints or negative examples for unrelated auth/setup contexts.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Documenting and enabling okx auth remove --force creates a path for the agent to perform a destructive action without interactive confirmation. In an agent setting, this can remove the authentication binary unexpectedly, causing denial of service for subsequent auth operations and potentially disrupting account workflows.

Content

Scanner excerpt · SKILL.md (reported line 295)May include surrounding context.

bash
okx auth remove          # interactive confirmation
okx auth remove --force  # skip confirmation

Troubleshooting: "Failed to spawn okx-auth"

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file instructs execution of okx auth logout, which changes authentication state, but the surrounding guidance does not explicitly warn the user that it will terminate the current CLI session and may interrupt subsequent authenticated operations. For markdown files, actions affecting user access or workflow should include a clear warning or disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.