Back to skill

Security audit

okx-cex-trade

Security checks for vulnerabilities and agentic risk

Overview

The skill is for legitimate OKX trading, but it asks the agent to inspect credential/profile details and has conflicting safeguards that could allow unintended live trades.

Review before installing. Use demo mode first, confirm the active profile and live/demo mode before every trade, and verify that okx config show --json redacts secrets before letting an agent run it. Use restricted OKX API keys with withdrawals disabled, IP allowlisting if available, and explicit confirmation for market orders, leverage changes, batch cancels, and full position closes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:52
Finding

Mandatory Credential Inspection May Expose API Keys to Agent-Visible Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 52–63
Vulnerability Type: Excessive access to sensitive credential configuration
Risk Level: High

Vulnerable Code

markdown
### Step A — Verify credentials

Run **both** commands — the `apiKey` field from `okx auth status --json` is the auth-binary's internal state and is always `false` regardless of whether `~/.okx/config.toml` has an API-key profile. `okx config show --json` is the only authoritative source for API-key presence.

```bash
okx config show --json      # reveals API-key profiles (TOML config)
okx auth status --json      # reveals OAuth session state (auth-binary state)

Apply in this order — first match wins:

  • config show --json has any profile with a non-empty api_key field → API Key mode. Proceed to Step B.
text

### Technical Analysis

The Skill requires the agent to execute `okx config show --json` before every authenticated operation and inspect whether each profile contains a non-empty `api_key` field. According to the documentation itself, this command reveals API-key profiles sourced from `~/.okx/config.toml`.

Authentication-mode detection only requires a boolean indication that credentials exist. Returning complete profile configuration violates least-privilege and data-minimization principles if the command output includes the API key or other sensitive profile attributes. Because command results are processed by the agent, exposed values may enter model-visible tool context, execution logs, telemetry, or retained conversation records.

No evidence was found that the Skill intentionally transmits credentials to an external party. The vulnerability is the unnecessary exposure of credential configuration rather than confirmed exfiltration.

### Attack Path

1. A user requests any authenticated OKX operation.
2. The Skill applies its mandatory credential-check procedure.
3. The agent executes `okx confi
...[truncated 1197 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace okx config show --json with a dedicated authentication-status command that returns only:
    • Whether credentials are configured
    • Authentication method
    • Profile name
    • Demo or live mode
  2. Ensure the CLI never emits API keys, secrets, passphrases, OAuth tokens, or other reusable credentials to standard output.
  3. Represent credential presence as a boolean such as "api_key_configured": true rather than returning the credential field.
  4. Redact sensitive configuration values at the CLI serialization layer, not only in the Skill's presentation logic.
  5. Query only the selected profile instead of enumerating every configured profile.
  6. Add automated tests verifying that secrets cannot appear in JSON output, terminal output, errors, debug logs, or telemetry.
  7. Document that agent-visible tools must not read raw credential files or return reusable authentication material.
  8. Recommend narrowly scoped API keys, IP allowlisting, withdrawal-disabled trading keys, and periodic key rotation as defense-in-depth controls.

T09 · Insecure Skill Coding Practices

Error
Location
references/event-workflows.md:242
Finding

Event-Contract Workflow Bypasses Mandatory Authentication and Trading-Mode Preflight

Content
View full analysis

Vulnerability Details

File Location: references/event-workflows.md, lines 242–246
Vulnerability Type: Conflicting safety instructions permit financial writes without mandatory preflight
Risk Level: High

Vulnerable Code

markdown
## Key Rules for AI Agents

1. **Place directly after user confirms** — no pre-flight check required.
2. **Check settlement.method**: determines which outcomes apply (UP/DOWN for `price_up_down`; YES/NO for `price_above`/`price_once_touch`).
3. **Confirm outcome with user** if unclear.

This conflicts with the global requirements in SKILL.md, including the instructions to run credential and profile checks before authenticated commands, determine the trading mode, and confirm write parameters.

Technical Analysis

Event-contract placement is a financial write operation. The event-specific workflow explicitly states that no preflight check is required and instructs the agent to place an order directly after user confirmation. This can override or weaken the global safeguards because agents commonly apply the most specific workflow associated with the active operation.

The global documentation establishes that OAuth uses live trading by default unless --demo is supplied. API-key operation similarly depends on selecting the correct live or demo profile. Skipping preflight therefore allows a stale, implicit, or incorrectly selected environment to control execution.

User confirmation of an order does not necessarily confirm the active account, authentication method, credential profile, or live/demo environment. Consequently, an otherwise valid confirmation may authorize an order in a different environment from the one the user intended.

Attack Path

  1. An OAuth session or API-key profile is already active from an earlier operation.
  2. The user requests an event-contract trade and confirms the contract details.
  3. The agent loads the event workflow and follows the ...[truncated 1253 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the conflicting instruction with:

    After user confirmation, perform the mandatory credential, profile, and trading-mode preflight before placing the event-contract order.

  2. Require explicit live/demo resolution immediately before every financial write, including place, amend, cancel, close, and leverage operations.
  3. Never rely on OAuth's implicit live default. Require an explicit environment argument or a separately validated session setting.
  4. For API-key authentication, require an explicitly selected profile whose environment matches the user's confirmed mode.
  5. Include the account/profile identifier and [mode: live] or [mode: demo] in the final confirmation shown before execution.
  6. Fail closed when the environment is missing, stale, ambiguous, or inconsistent with conversation context.
  7. Centralize preflight enforcement so module-specific workflow documents cannot bypass it.
  8. Add automated policy tests proving that every event-contract write passes through authentication, profile, mode, instrument, outcome, size, and order-type validation.
  9. Require renewed confirmation if any order parameter or execution environment changes after the user's original confirmation.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/event-workflows.md (reported line 3)May include surrounding context.

md
# Event Contract Workflows — Multi-Step Trading Scenarios

> **Display rule**: When presenting tool results to users, always use user-facing labels
> (e.g., "Order number", "Contract", "Fill price"), not raw API field names
> (e.g., `ordId`, `instId`, `fillPx`).

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section directs the agent to analyze candles, recommend UP or DOWN, assign confidence, and present a trading recommendation to the user. That goes beyond execution-only behavior and introduces investment-advice-like autonomous judgment, which is risky because it can drive financially consequential decisions without an appropriately scoped advisory mandate or stronger user consent controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Although the text notes the command closes the entire position at market price, it lacks a strong, prominent warning that this is an immediate full liquidation action and that --autoCxl may cancel pending orders beforehand. In a trading skill, that omission is especially dangerous because a mistaken invocation can irreversibly exit a large leveraged position and disrupt associated order protection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation references okx bot grid-orders and stopping bots while the metadata explicitly says this skill must not be used for bots. Cross-domain guidance like this can cause an agent to inspect or influence bot-management workflows that are out of scope, undermining least privilege and potentially affecting automated trading systems the user did not intend to touch.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest explicitly says 'Do NOT use for market data (okx-cex-market)', but the skill routes event-contract browsing/discovery to this skill and documents read operations like okx event browse, okx event series, and okx event markets. Those are market-discovery/data retrieval capabilities rather than order placement/cancellation/amendment, so the documented behavior exceeds the manifest's stated exclusion of market data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest says not to use this skill for 'account balance (okx-cex-portfolio)', and the routing section assigns balances, P&L, positions, fees, and transfers to the portfolio skill. However, this skill also advertises and instructs use of position-query commands such as okx swap positions, okx futures positions, and okx option positions, which are portfolio/account-state reads rather than pure trade execution.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
77% confidence
Finding

The instruction that read commands should 'run immediately' can trigger authenticated account/order/position queries based on remembered session context without a fresh per-request confirmation. In a trading skill handling sensitive financial data, this increases the risk of unintended disclosure or use of stale session state, especially when mode, account, or user intent may have changed.

Content

Scanner excerpt · SKILL.md (reported line 392)May include surrounding context.

md
For cross-skill workflows and step-by-step examples, read `{baseDir}/references/workflows.md`.

### Step 2 — Confirm profile, then confirm write parameters

**Read commands** (orders, positions, fills, get, get-leverage, algo orders): run immediately.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 415)May include surrounding context.

md
### Error-suggested remediation safeguard

When an OKX API error message suggests a fix that involves **write operations** (cancel orders, close positions, stop bots/strategies, transfer funds, etc.), you **MUST NOT** automatically execute those actions. Instead:

1. **Report** the error and its suggestion to the user verbatim
2. **Diagnose** — run read-only queries to identify what is blocking (e.g., `algo-orders --status pending`, `positions`, `bot grid-orders --status active`)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow explicitly instructs the agent to use market-data and account-position commands even though the manifest says this skill should only be used for trading execution and not for market data or portfolio tasks. That scope expansion can cause the wrong skill to access broader account information or perform analysis functions outside the user's intended tool boundary, weakening least-privilege and increasing the chance of unintended data exposure or misuse.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

The instruction to automatically run settlement checks for expired positions 'without asking' authorizes additional tool use beyond the immediate user request. Although read-only, it still permits autonomous account- or market-related actions, which erodes user control and can normalize silent tool invocation in a financial context.

Content

Scanner excerpt · references/event-workflows.md (reported line 135)May include surrounding context.

  • Infer expiry from the instrument ID (instId, API field):
    • price_above / price_once_touch: YYMMDD-HHMM → e.g. 260320-1600 = 2026-03-20 16:00 UTC+8
    • price_up_down: YYMMDD-START-END → expiry is the END time
  • If expired → immediately run without asking:
    text
    okx event markets <seriesId> --state expired
    

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/event-workflows.md (reported line 175)May include surrounding context.

User: "Cancel order EVT-ORDER-001" / "Cancel my order 800000024"

okx event cancel requires both the instrument ID and Order number. If the user only provides the Order number, look up the instrument ID first — never ask the user for it.

text
Step 1: okx event orders --status open

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill metadata says it covers conditional TP/SL/trailing algo orders, but this reference also documents additional futures algo order types such as trigger, chase, iceberg, and TWAP. That scope expansion can cause an agent to invoke trading capabilities that were not declared in the manifest, weakening policy boundaries and potentially enabling unexpected order placement behaviors in a high-risk financial context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The troubleshooting section tells the agent to inspect bot-related state using bot commands even though the manifest explicitly says bots are out of scope for this skill. In a trading skill, cross-skill operational guidance can bypass intended capability boundaries and lead an agent to access or act on unrelated automation features during error handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file gives conflicting guidance about option TP/SL support: earlier sections document attached TP/SL parameters for okx option place and an okx option algo amend flow, but the edge-case note says 'No TP/SL algo on options'. In a trading-execution skill, this ambiguity can cause an agent or user to choose the wrong command path, fail to protect positions, or incorrectly assume risk controls are unavailable or unsupported.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file documents account-impacting trading operations including placing, amending, and canceling orders, TP/SL algos, and setting spot margin leverage, but it provides no explicit guardrails requiring user confirmation, risk disclosure, or verification before execution. In an AI-agent context, this is dangerous because the content directly enables live financial actions; ambiguous user requests or prompt injection elsewhere could cause unintended trades, order cancellations, or leverage changes with immediate monetary loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This reference documents live order placement for leveraged swap products without an upfront warning that these actions can create real market exposure, incur losses, and may be irreversible once submitted or filled. In an agent context, omission of prominent risk framing increases the chance that a user or downstream system treats examples as routine commands rather than financially destructive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The leverage section explains mechanics and exchange constraints but does not prominently warn that changing leverage can materially increase liquidation risk and affect existing positions, especially in isolated/hedge setups. Because this skill directly supports leveraged derivatives trading, missing safety framing makes harmful misuse more likely than in a non-financial context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file instructs operators to run account-configuration checks (okx account config) to determine account mode, which extends behavior beyond the stated trading-only purpose. Even if read-only, this broadens the operational scope of the skill and can cause agents to access adjacent account-management functions not disclosed in the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation adds advanced algo order types such as trigger, chase, iceberg, and TWAP beyond the capability scope described in the skill metadata, which only explicitly claims standard order placement/amend/cancel flows plus conditional TP/SL/trailing. This creates scope drift: an agent relying on the manifest may invoke higher-risk execution behaviors the user or platform did not expect, increasing the chance of unintended trading strategies or bypass of approval assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This reference documents high-impact trading and order-management actions, including market, leverage, close-position, and TP/SL operations, but it does not include an explicit warning that these actions can cause immediate financial loss or irreversible account changes. In a skill intended to drive live exchange operations, omission of such caution increases the risk of users or downstream agents invoking destructive actions without adequate confirmation or risk awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow examples include user utterances and agent responses in Chinese at L111-L141, but the document does not indicate that the skill is region-specific or that users may choose their preferred language. This can violate language/locale policy by implicitly enforcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 422)May include surrounding context.

md
3. **Present findings** — show the user what was found and which specific items would need to be cancelled/closed/stopped
4. **Wait for explicit confirmation** before executing any remediation

This applies to all error codes whose messages suggest destructive actions, including but not limited to:
- Set-leverage blocked by pending algo orders or active bots
- Account setting changes requiring order/position/strategy cleanup (e.g., error codes 59000, 59002, 59007)
- Margin mode switches requiring position closure

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is described as an OKX trading skill and explicitly says not to use it for account balance/portfolio or bots. This reference tells the operator to run okx account config, which is an account-management capability outside the declared trading-only scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.