Back to skill

Security audit

okx-cex-market

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-only OKX market-data helper, but its install instructions can fetch and globally install an unpinned CLI version that was not the reviewed artifact.

Review this before installing. The market-data behavior is coherent, but install only if you trust the npm package and publisher; prefer pinning the command to `@okx_ai/okx-trade-cli@1.3.7` or using a locally scoped install instead of the documented global unpinned install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:38
Finding

Unpinned Global Installation of an Unauditable Third-Party CLI

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 38–41
Vulnerability Type: Supply-chain risk from an unpinned executable dependency
Risk Level: Medium

Vulnerable Code

bash
## Install

npm install -g @okx_ai/okx-trade-cli
okx market ticker BTC-USDT   # verify

Although the metadata at lines 14–18 identifies @okx_ai/okx-trade-cli@1.3.7, the installation instructions actually executed by a user do not pin that version.

Technical Analysis

The command installs the npm registry's current version rather than the declared and reviewed version 1.3.7. Consequently, the executable installed at runtime may differ from the dependency version represented in the Skill metadata.

The dependency's implementation and a corresponding lockfile are not included in the audited project. Its install-time scripts, network destinations, profile handling, filesystem access, and runtime behavior therefore could not be verified in this audit. npm packages can run lifecycle scripts during installation, while later okx invocations execute package code with the invoking user's privileges.

Global installation expands the exposure because it places an executable in a system- or user-wide command path. This behavior exceeds the minimum privilege needed to obtain public market data when a pinned, locally scoped dependency would suffice.

Attack Path

  1. An attacker compromises the npm publisher account, package release process, or an upstream dependency.
  2. The attacker publishes a malicious release under @okx_ai/okx-trade-cli.
  3. A user or Agent follows the documented unpinned command:
    bash
    npm install -g @okx_ai/okx-trade-cli
    
  4. npm resolves the latest release rather than the metadata-declared 1.3.7 release.
  5. Malicious package lifecycle code may execute during installation, or malicious runtime code executes when the documented okx verification or market commands are invoked.

...[truncated 701 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the operational installation command to the same reviewed version declared in metadata:
    bash
    npm install -g @okx_ai/okx-trade-cli@1.3.7
    
  2. Prefer a project-local, pinned installation over a global installation, then invoke the exact local binary.
  3. Commit a lockfile containing integrity hashes, or otherwise verify the package tarball against a trusted digest before installation.
  4. Verify package provenance, publisher identity, and signatures where supported.
  5. Disable npm lifecycle scripts with --ignore-scripts if the package does not require them; otherwise, separately audit every required lifecycle script.
  6. Include or link to auditable source code that corresponds exactly to the pinned package release.
  7. Run the CLI as an unprivileged user and restrict filesystem and network access to what public market-data retrieval requires.
  8. Keep the frontmatter version and every installation example synchronized to prevent accidental upgrades to unreviewed code.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

okx market ticker BTC-USDT # verify

text

Market data commands return the same public data regardless of demo/live mode — no API credentials required. If the user's profile has `demo=true` set and they want live data context, they can use `--live` to confirm they are in live mode (it has no effect on public market data but clarifies environment). Always inform the user which environment is active (demo or live) when it is relevant to their query. No confirmation needed before running any market command. Add `--json` to any command for raw OKX API v5 response. Add `--env` to wrap the output as `{"env", "profile", "data"}`.

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
### Step 2 — Run commands immediately

All market data commands are read-only — no confirmation needed.

### Step 3 — No writes, no verification needed

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
All market data commands are read-only — no confirmation needed.

### Step 3 — No writes, no verification needed

All commands in this skill are read-only.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest frames this skill as read-only market-data access and explicitly says not to use it for order placement, but these notes tell the reader to verify prices 'before placing orders.' That wording does not mean the file itself performs trading, but it does actively blur the documented intent by discussing order-placement workflows within this skill's docs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section is documentation-only, but it explicitly discusses order behavior and tells users to confirm price before placing a stock token order. Because the manifest says this skill should not be used for placing or cancelling orders, that instruction contradicts the documented boundary between market-data and trading skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.