Back to skill

Security audit

okx-cex-earn

Security checks for vulnerabilities and agentic risk

Overview

This OKX Earn skill is mostly purpose-aligned, but it needs review because it operates on live funds while under-disclosing some live-order, credential-profile, dependency, and recurring-monitoring risks.

Install only if you trust the OKX CLI package and are comfortable letting the agent operate against live OKX Earn funds. Use least-privilege credentials, avoid Withdraw permission unless you intend transfers, review every confirmation carefully, and avoid recurring /loop monitors unless you explicitly want ongoing financial notifications.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Security-Critical Operations Delegated to an Unverified Global npm Dependency

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:39
Finding

Mandatory Credential-Profile Inspection Exposes API-Key Material to Agent-Visible Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (14)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instruction to 'always use live mode silently' removes an important user safety checkpoint for actions that can move or lock real funds. Because this skill supports subscriptions, redemptions, rate setting, and other authenticated writes, suppressing a clear real-money warning materially increases the risk of unintended financial loss.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

md
- **Security:** Never ask users to paste API keys or secrets into chat.
- **Output:** Always pass `--json` to list/query commands and render results as a Markdown table — never paste raw terminal output.
- **Network errors:** If commands fail with a connection error, prompt user to check VPN: `curl -I https://www.okx.com`
- **Language:** Always respond in the user's language.

For number/time formatting and response structure conventions, read `{baseDir}/references/templates.md`.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/savings-commands.md (reported line 222)May include surrounding context.

md
**NEVER expose raw state values** to the user — always translate using the table above.

**Display rules:**
- Render as Markdown table with columns: # · reqId · Currency · Amount · Rate · Term · Status · Accrued Interest · Create Time
- Format timestamps using `YYYY/M/D HH:MM`
- For `pending` orders, note that early redemption is available

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description contains very broad trigger terms such as generic 'earn', '理财', 'fixed deposit', and 'idle funds', which can cause the agent to invoke this skill in ambiguous contexts. In a financial skill that performs authenticated, real-funds operations, overbroad routing increases the chance of misclassification and accidental exposure to high-risk workflows.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 228)May include surrounding context.

md
## Global Notes

- **Security:** Never ask users to paste API keys or secrets into chat.
- **Output:** Always pass `--json` to list/query commands and render results as a Markdown table — never paste raw terminal output.
- **Network errors:** If commands fail with a connection error, prompt user to check VPN: `curl -I https://www.okx.com`
- **Language:** Always respond in the user's language.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This command performs a live DCD subscription purchase on a --profile live account, but the documentation does not clearly warn that it will place a real order using actual funds. In an agent-driven workflow, that omission increases the chance of accidental execution from ambiguous user intent, especially because DCD is a structured product with conversion and settlement risks rather than a simple read-only query.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The redemption flow immediately executes a live early redemption after fetching a quote, yet the documentation does not prominently warn that this can realize gains or losses and cannot be treated as a harmless preview. In a financial agent context, users may believe they are only checking eligibility or terms, leading to unintended liquidation behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The earn onchain cancel operation can affect pending real-fund on-chain orders, but this section provides no mandatory summary, risk warning, or explicit user confirmation before cancellation. In a financial skill, omission of a confirmation gate increases the chance of accidental or socially engineered order cancellation, potentially causing missed yield opportunities, timing losses, or user confusion about fund state.

Content

No source excerpt is available for this finding.

Behavior Manipulation

Medium
Category
Prompt Injection
Confidence
75% confidence
Finding

Subtle instructions detected that may alter agent decision-making or introduce hidden biases.

Content

Scanner excerpt · references/savings-commands.md (reported line 63)May include surrounding context.

okx --profile live earn savings set-rate --ccy USDT --rate 0.01

text

`--rate` is the user's minimum matching threshold — funds are lent only when the market lending rate ≥ this value. The actual yield is always `lendingRate`. Never tell users that lowering their minimum rate reduces earnings — this is incorrect.

---

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains a natural-language formatting rule that says to convert timestamps to the user's timezone, but if unknown, to default to UTC+8. That forces a specific locale behavior without user choice or clear region-specific justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This workflow instructs the agent to create recurring monitoring and recommendation behavior, which expands the skill from on-demand portfolio actions into autonomous background activity. In a financial context, persistent monitoring can cause unsolicited prompts, repeated recommendations, and eventual execution-adjacent nudging outside the user’s immediate request scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The recurring monitor trigger phrases are broad enough to match general requests like 'monitor fixed earn for me' without forcing collection of essential scope such as currency, interval, duration, and what actions are allowed. In a finance skill, that ambiguity can lead the agent to set up semi-autonomous behavior the user did not precisely authorize.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The Flash Earn workflow adds persistent alerting logic with state tracking across loop sessions, which is materially different from direct OKX Earn management via CLI. That broadens the skill into notification automation and increases the chance of overreach, user confusion, or abuse through repeated financial prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The Flash Earn notification trigger is vague and can overlap with ordinary reminder or interest-check requests, making it easy for the agent to initiate persistent notifications from casual language. Because the domain is investment products, repeated unsolicited alerts can pressure user action and exceed the intended scope of the original request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.