Back to skill

Security audit

Okx Onchain Gateway

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent blockchain gateway purpose, but it needs review because it can automatically install mutable remote code and broadcast signed on-chain transactions without clear safety confirmations.

Review this skill before installing. It is designed for real blockchain operations, so only use it when you understand that broadcasting a signed transaction may move funds or change on-chain state. Prefer installing and verifying the onchainos CLI yourself from a trusted, pinned release, and avoid letting routine requests trigger automatic remote installer execution or updates.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:19
Finding

Automatic Retrieval and Execution of a Mutable Remote Installer

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
**When the swap skill flags a transaction for MEV protection**, ensure the broadcast request includes the appropriate parameters. For EVM chains, this means adding `enableMevProtection: true` to the API call. For Solana, use the `tips` parameter for Jito bundling.

## Amount Display Rules

- Gas prices in Gwei for EVM chains (`18.5 Gwei`), never raw wei
- Gas limit as integer (`21000`, `145000`)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs the agent to broadcast signed transactions and to download and execute installer scripts, but it does not prominently warn that transaction broadcasts are irreversible or that pre-flight setup may run newly fetched code from the network. In a wallet/on-chain context, missing consent and safety disclosures increase the risk of unintended fund loss or unsafe code execution by normalizing high-risk actions as routine steps.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

  1. Resolve latest stable version: Fetch the latest stable release tag from the GitHub API:
    text
    curl -sSL "https://api.github.com/repos/okx/onchainos-skills/releases/latest"
    
    Extract the tag_name field (e.g., v1.0.5) into LATEST_TAG. If the API call fails and onchainos is already installed locally, skip steps 2-3

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The broadcast command accepts a fully signed transaction and submits it to a live blockchain, which is typically irreversible once propagated and confirmed. Documenting this action without an explicit warning can mislead users into treating it like a harmless dry-run or status check, increasing the chance of accidental fund transfers or unintended contract execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.