Back to skill

Security audit

Okx Dex Trenches

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly read-only OKX meme-token research, but it needs Review because it expands into WebSocket/API-credential workflows and wallet/payment-adjacent handling that are not cleanly scoped.

Install only if you are comfortable with an OKX-backed CLI being installed or updated locally, with wallet addresses you provide being sent for analytics, and with the skill potentially entering WebSocket monitoring flows. Avoid providing API credentials or wallet addresses unless needed for the specific query, and treat any payment/quota prompt carefully before confirming.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata and body establish a read-only boundary and explicitly say WebSocket script/bot use should route to a different skill, but later instructions directly invoke onchainos ws commands from this skill. That inconsistency can cause the agent to exceed the declared capability boundary, select the wrong skill, or perform real-time monitoring behavior that bypasses the intended routing and safety controls.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · _shared/preflight.md (reported line 9)May include surrounding context.

  1. Resolve latest stable version: Fetch the latest stable release tag from the GitHub API:
    text
    curl -sSL "https://api.github.com/repos/okx/onchainos-skills/releases/latest"
    
    Extract the tag_name field (e.g., v1.0.5) into LATEST_TAG. If the API call fails and onchainos is already installed locally, skip steps 2-3

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Line L053 instructs the skill to take special handling whenever the user's query contains Chinese text, rather than offering this as an optional or user-selected behavior. This is a mild language/locale policy concern because it applies a language-based routing rule automatically without explicit opt-in or a documented necessity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The --wallet-address filter allows wallet-specific analytics, but the documentation gives no warning that the supplied address may be sent to a remote service and used to tailor results. In a tool focused on meme-token research and trader behavior, this can reveal a user's portfolio interests and trading patterns beyond what they may expect from a simple filter.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The command reference documents an optional --wallet parameter that sends a user's wallet address to obtain position/P&L data, but it does not disclose that this is wallet-specific analytics involving transmission of an address. Wallet addresses are pseudonymous but still sensitive in an on-chain research context because they can be linked to holdings, behavior, and identity across sessions or services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The aped-wallet command supports a --wallet option to highlight the user's wallet in the returned list, but the docs omit any privacy disclosure about sending that wallet address for personalization. Even though blockchain addresses are public, highlighting and correlating a user's wallet with same-car trading analysis can expose behavioral profiling and reduce user privacy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.