Back to skill

Security audit

okx-cex-earn

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed OKX Earn automation guide that can move real funds, but its risky actions are purpose-aligned and generally require user confirmation.

Install only if you intend to let an agent use your authenticated OKX profile for live Earn actions. Review each confirmation carefully, especially Dual Investment, on-chain staking, redemptions, transfers, and recurring monitors, because these can lock funds, convert assets, stop earnings, or change real balances.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description contains very broad trigger phrases such as generic references to idle funds, earning, savings, and wealth-management concepts. In an agent-routing system, this can cause the skill to be invoked for loosely related financial queries, increasing the chance of unintended authenticated actions or exposing users to high-risk financial product flows they did not explicitly request.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This documentation describes a command that immediately places a live Dual Investment order but does not clearly foreground that it is a real trade affecting user funds. In this skill context, users may treat the command as informational or low-risk, yet settlement can convert both principal and yield into another currency, creating material financial loss or unwanted asset conversion if the agent executes it without an explicit warning and confirmation step.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The redemption command is documented as a two-step internal flow that immediately executes after fetching a quote, but it does not clearly warn users that this is an irreversible live action that may realize a loss. In a financial automation skill, that omission is dangerous because a user could intend to inspect redemption terms only and instead trigger an actual redemption with negative `termRate` and unexpected fund movement.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The `earn onchain cancel` command changes the state of a live financial order, but this section provides no explicit pre-execution warning, summary, or requirement for user confirmation. In a skill that manages real funds on a live OKX profile, an accidental or ambiguous cancel action could interrupt intended investments or alter asset flow, making this a genuine safety/control weakness even if the monetary impact is usually less severe than an unauthorized purchase or redeem.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.