T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Security-Critical Operations Delegated to an Unverified Global npm Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This OKX Earn skill is mostly purpose-aligned, but it needs review because it operates on live funds while under-disclosing some live-order, credential-profile, dependency, and recurring-monitoring risks.
Install only if you trust the OKX CLI package and are comfortable letting the agent operate against live OKX Earn funds. Use least-privilege credentials, avoid Withdraw permission unless you intend transfers, review every confirmation carefully, and avoid recurring /loop monitors unless you explicitly want ongoing financial notifications.
SKILL.md:13Security-Critical Operations Delegated to an Unverified Global npm Dependency
SKILL.md:39Mandatory Credential-Profile Inspection Exposes API-Key Material to Agent-Visible Output
The instruction to 'always use live mode silently' removes an important user safety checkpoint for actions that can move or lock real funds. Because this skill supports subscriptions, redemptions, rate setting, and other authenticated writes, suppressing a clear real-money warning materially increases the risk of unintended financial loss.
Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.
- **Security:** Never ask users to paste API keys or secrets into chat.
- **Output:** Always pass `--json` to list/query commands and render results as a Markdown table — never paste raw terminal output.
- **Network errors:** If commands fail with a connection error, prompt user to check VPN: `curl -I https://www.okx.com`
- **Language:** Always respond in the user's language.
For number/time formatting and response structure conventions, read `{baseDir}/references/templates.md`.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
**NEVER expose raw state values** to the user — always translate using the table above.
**Display rules:**
- Render as Markdown table with columns: # · reqId · Currency · Amount · Rate · Term · Status · Accrued Interest · Create Time
- Format timestamps using `YYYY/M/D HH:MM`
- For `pending` orders, note that early redemption is available
The skill description contains very broad trigger terms such as generic 'earn', '理财', 'fixed deposit', and 'idle funds', which can cause the agent to invoke this skill in ambiguous contexts. In a financial skill that performs authenticated, real-funds operations, overbroad routing increases the chance of misclassification and accidental exposure to high-risk workflows.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Global Notes
- **Security:** Never ask users to paste API keys or secrets into chat.
- **Output:** Always pass `--json` to list/query commands and render results as a Markdown table — never paste raw terminal output.
- **Network errors:** If commands fail with a connection error, prompt user to check VPN: `curl -I https://www.okx.com`
- **Language:** Always respond in the user's language.
This command performs a live DCD subscription purchase on a --profile live account, but the documentation does not clearly warn that it will place a real order using actual funds. In an agent-driven workflow, that omission increases the chance of accidental execution from ambiguous user intent, especially because DCD is a structured product with conversion and settlement risks rather than a simple read-only query.
The redemption flow immediately executes a live early redemption after fetching a quote, yet the documentation does not prominently warn that this can realize gains or losses and cannot be treated as a harmless preview. In a financial agent context, users may believe they are only checking eligibility or terms, leading to unintended liquidation behavior.
The earn onchain cancel operation can affect pending real-fund on-chain orders, but this section provides no mandatory summary, risk warning, or explicit user confirmation before cancellation. In a financial skill, omission of a confirmation gate increases the chance of accidental or socially engineered order cancellation, potentially causing missed yield opportunities, timing losses, or user confusion about fund state.
Subtle instructions detected that may alter agent decision-making or introduce hidden biases.
okx --profile live earn savings set-rate --ccy USDT --rate 0.01
`--rate` is the user's minimum matching threshold — funds are lent only when the market lending rate ≥ this value. The actual yield is always `lendingRate`. Never tell users that lowering their minimum rate reduces earnings — this is incorrect.
---
This markdown file contains a natural-language formatting rule that says to convert timestamps to the user's timezone, but if unknown, to default to UTC+8. That forces a specific locale behavior without user choice or clear region-specific justification, which matches the language/locale policy violation criteria.
This workflow instructs the agent to create recurring monitoring and recommendation behavior, which expands the skill from on-demand portfolio actions into autonomous background activity. In a financial context, persistent monitoring can cause unsolicited prompts, repeated recommendations, and eventual execution-adjacent nudging outside the user’s immediate request scope.
The recurring monitor trigger phrases are broad enough to match general requests like 'monitor fixed earn for me' without forcing collection of essential scope such as currency, interval, duration, and what actions are allowed. In a finance skill, that ambiguity can lead the agent to set up semi-autonomous behavior the user did not precisely authorize.
The Flash Earn workflow adds persistent alerting logic with state tracking across loop sessions, which is materially different from direct OKX Earn management via CLI. That broadens the skill into notification automation and increases the chance of overreach, user confusion, or abuse through repeated financial prompts.
The Flash Earn notification trigger is vague and can overlap with ordinary reminder or interest-check requests, making it easy for the agent to initiate persistent notifications from casual language. Because the domain is investment products, repeated unsolicited alerts can pressure user action and exceed the intended scope of the original request.
No suspicious patterns detected.