Back to skill

Security audit

Okx Dex Signal

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed OKX on-chain market data helper, with some install, payment, and WebSocket handling users should understand before using it.

Install this only if you are comfortable with the OKX onchainos CLI being installed or updated from OKX GitHub releases and connecting to OKX services. Use least-privilege OKX API keys for WebSocket access, keep .env files out of version control, review any x402/payment confirmation carefully, and treat signal output as untrusted market data rather than trading advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description contains many broad trigger phrases such as generic terms for signals, whales, top traders, and quota/payment handling, which can cause this skill to activate for loosely related user requests. Over-broad routing increases the attack surface by pulling the model into a more privileged or specialized workflow than necessary, potentially leading to unintended command suggestions or incorrect tool selection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata explicitly says WebSocket scripts/bots should use a different skill, but this file still provides direct WebSocket commands and points users to a protocol spec. That inconsistency can bypass intended skill boundaries and cause the wrong skill to handle real-time monitoring or bot-building requests, increasing the chance of unsafe tool use, policy drift, or accidental invocation of lower-level capabilities.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _shared/preflight.md (reported line 9)May include surrounding context.

  1. Resolve latest stable version: Fetch the latest stable release tag from the GitHub API:
    text
    curl -sSL "https://api.github.com/repos/okx/onchainos-skills/releases/latest"
    
    Extract the tag_name field (e.g., v1.0.5) into LATEST_TAG. If the API call fails and onchainos is already installed locally, skip steps 2-3

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The instruction says that if the user's query contains Chinese text, the agent should read a Chinese keyword glossary for command mappings. This imposes language-based behavior automatically from text detection rather than an explicit user language choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file is structured around a fixed Chinese-to-English term mapping and does not indicate whether users may interact in other languages or choose a preferred locale. Because SQP-3 applies to natural-language policy concerns in any file, this can be treated as a mild language/locale constraint that is undocumented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file instructs clients to send API key, passphrase, timestamp, and signature in a login message, which is a privacy- and security-relevant operation. While it notes not to hardcode credentials, it does not explicitly warn users that the skill or client will transmit sensitive authentication material to a third-party service during login.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.