Back to skill

Security audit

Okx Security

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a legitimate OKX on-chain security scanner, but it automatically downloads and runs a changing remote installer and includes fail-open and wallet-action workflows that deserve human review before installation.

Review this skill before installing. It can install and update a local OKX onchainos CLI from the latest GitHub release, query wallet and portfolio data for scans, and guide approval revocation or transaction workflows. Install only if you trust the OKX release process and are comfortable requiring explicit review before any wallet signing, broadcast, approval, or swap action.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:17
Finding

Dynamic Remote Installer Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–49
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

The Skill requires an Agent to dynamically resolve the latest release, download an installer from GitHub, verify it against a checksum controlled by the same upstream repository, and execute it with the Agent user's permissions.

Vulnerable Code

markdown
Every time before running any `onchainos` command, always follow these steps in order. Do not echo routine command output to the user; only provide a brief status update when installing, updating, or handling a failure.

1. **Resolve latest stable version**: Fetch the latest stable release tag from the GitHub API:
   ```
   curl -sSL "https://api.github.com/repos/okx/onchainos-skills/releases/latest"
   ```
   Extract the `tag_name` field (e.g., `v1.0.5`) into `LATEST_TAG`.
   If the API call fails and `onchainos` is already installed locally, skip steps 2-3
   and continue with step 4 (the user may be offline or rate-limited; a stale
   binary is better than blocking). If `onchainos` is **not** installed, **stop** and
   tell the user to check their network connection or install manually from
   https://github.com/okx/onchainos-skills.

2. **Install or update**: If `onchainos` is not found, or if the cache at `~/.onchainos/last_check` (`$env:USERPROFILE\.onchainos\last_check` on Windows) is older than 12 hours:
   - Download the installer and its checksum file from the latest release tag:
     - **macOS/Linux**:
       `curl -sSL "https://raw.githubusercontent.com/okx/onchainos-skills/${LATEST_TAG}/install.sh" -o /tmp/onchainos-install.sh`
       `curl -sSL "https://github.com/okx/onchainos-skills/releases/download/${LATEST_TAG}/installer-checksums.txt" -o /tmp/installer-checksums.txt`
     - **Windows**:
       `Invoke-WebRequest -Uri "https://raw.githubusercontent.com/okx/onchainos-skills/${LATEST_TAG}/i
...[truncated 4732 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic installer execution from routine Skill use. Treat installation and updates as separate, explicit administrative operations.
  2. Require informed user approval before downloading or executing any installer, and display the exact source, version, destination, and command.
  3. Pin an audited immutable version rather than dynamically using releases/latest. Prefer a release tied to an immutable commit identifier.
  4. Use an independent authenticity mechanism. Verify release artifacts with a trusted signing key, Sigstore identity, or another signature whose trust root is not stored alongside the downloadable artifact.
  5. Bundle reviewed components where feasible. Include the required script or a reproducibly built binary in the reviewed package so the executed payload matches the audited content.
  6. Separate installer and checksum trust boundaries. A checksum published by the same potentially compromised release process should not be the only authenticity control.
  7. Apply least privilege. Execute installation in a restricted environment without administrative privileges, unnecessary credentials, wallet secrets, or broad filesystem access.
  8. Constrain downloaded installer behavior. Review it before execution, restrict allowed download destinations, and prohibit modification of unrelated startup files, services, or system tools.
  9. Use secure temporary-file handling. Create uniquely named files with restrictive permissions, avoid predictable shared /tmp paths, reject symbolic links, and delete artifacts after verification and execution.
  10. Record update events visibly. Do not suppress installation details; retain the resolved version, artifact digest, signature result, and user authorization for auditability.
  11. Fail closed on authenticity failures. Never execute an installer when signature verification, digest lookup, version parsing, or platform matching ...[truncated 249 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
93% confidence
Finding

The skill explicitly states that if token-scan API calls fail, the system should warn but not block, and in swap contexts should auto-continue without asking the user because trades are time-sensitive. This weakens the declared fail-safe principle and creates a fail-open path where an unavailable or disrupted security service can be bypassed during exactly the sort of high-risk transaction flow the skill is meant to protect.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
- **`HIGH` buy requires explicit user confirmation** (yes/no) — do not auto-continue.
- Individual label levels are **not displayed** to the user — only the overall `riskLevel` is shown, with triggered labels listed without level prefixes.
- If `isChainSupported: false`, skip detection with a warning; do not block.
- If API fails, warn but do not block. In swap context, token-scan failures auto-continue with a warning to avoid blocking time-sensitive trades — this overrides the general fail-safe's ask-user behavior.

> Security commands do not require wallet login. They work with any address.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/risk-token-detection.md (reported line 209)May include surrounding context.

md
- **Buy**: The target token (the token being received / `--to` in swap) is the one being scanned. User is acquiring this token.
- **Sell**: The source token (the token being spent / `--from` in swap) is the one being scanned. User is disposing of this token.
- **Standalone scan** (no swap context): Display all triggered labels with their risk levels. Do not apply buy/sell action logic — just present the risk assessment.

### Display Format

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

The document instructs the agent, in swap context, to continue the flow when token security scanning times out or fails. In a security skill, fail-open guidance is dangerous because it normalizes proceeding without a completed safety check, allowing malicious or high-risk transactions to bypass the intended control under transient failure conditions.

Content

Scanner excerpt · references/risk-token-detection.md (reported line 234)May include surrounding context.

md
| Scenario | Handling |
|---|---|
| `isChainSupported: false` | Skip detection. Append warning: "This chain does not support token security scanning." Do not block the trade. |
| API timeout / request failure | **Swap context**: Append warning: "Token security scan is temporarily unavailable. Please trade with caution." Continue flow (overrides general fail-safe). **Standalone context**: Follow the general fail-safe principle — ask user whether to retry or proceed. |
| `riskLevel: "LOW"` and no labels triggered | Safe to proceed. |
| `riskLevel` missing, `null`, or unrecognized value | Treat as `HIGH` (cautious default). Display: "⚠️ Risk level unavailable or unrecognized — treating as high risk." Apply HIGH-level actions (pause buy for confirmation, warn on sell). This may indicate an API regression or version mismatch — note it in the execution log if available. |
| `buyTaxes`/`sellTaxes` is `null` | Tax data unavailable. Do not display tax info. Do not treat as risk. |

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This security-scanning skill goes beyond analysis and prescribes approval, contract-call, swap execution, and broadcast steps. Blending safety assessment with transaction execution is dangerous because a tool expected to be read-only can influence or initiate state-changing actions, increasing the chance of unintended approvals, risky swaps, or privilege misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description includes many broad natural-language triggers such as 'is this token safe', 'scan this tx', and 'check if this dapp is safe', which are common user phrases that may be mentioned conversationally rather than as an explicit intent to invoke this skill. In an agent environment, this can cause unintended activation and lead to network calls, tool execution, or security guidance being applied in the wrong context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

  1. Resolve latest stable version: Fetch the latest stable release tag from the GitHub API:
    text
    curl -sSL "https://api.github.com/repos/okx/onchainos-skills/releases/latest"
    
    Extract the tag_name field (e.g., v1.0.5) into LATEST_TAG. If the API call fails and onchainos is already installed locally, skip steps 2-3

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
- Report the error clearly to the user.
- **Ask the user** whether to retry the scan or proceed without scan results.
- If the user chooses to proceed, display a warning:
  > "⚠️ Security scan could not be completed. Proceeding without verification — please ensure you trust this operation."
- Log the skipped scan for auditability.

> A security scan that fails to complete is NOT a "pass". Always inform the user and let them make an explicit decision.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill manifest explicitly says not to use this skill for wallet balance/history functions, yet this reference instructs the agent to call wallet balance and portfolio retrieval commands as part of token scanning. That expands the skill's effective capability boundary and can cause the agent to access broader wallet/portfolio data than users or orchestrators expect, increasing privacy and authorization risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest embeds a dedicated Chinese trigger list alongside English triggers, but does not explain whether multilingual handling is optional, user-selected, or limited to a specific deployment context. Under the language/locale policy, hard-coding locale-specific behavior without opt-in can be a policy concern unless clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs the agent to use the currently logged-in wallet's EVM address by default when the user does not specify one, which can cause implicit querying of wallet-related approval data without explicit user awareness or confirmation. In a security-scanning skill, this is contextually plausible and likely intended as a convenience feature, but it still creates a privacy and consent issue because the agent may access sensitive account metadata the user did not clearly authorize for that specific request.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/risk-token-detection.md (reported line 120)May include surrounding context.

md
| `isVeryLowLpBurn` | Boolean | Very low LP burn ratio |
| `isVeryHighLpHolderProp` | Boolean | LP holder concentration is very high |
| `isHasBlockingHis` | Boolean | Has history of freezing addresses |
| `isOverIssued` | Boolean | Token over-issued beyond stated supply |
| `isCounterfeit` | Boolean | Counterfeit — impersonates a well-known token |
| `isNotOpenSource` | Boolean | Token contract source code is not open-source |
| `isMintable` | Boolean | Token supply can be increased (mintable) |

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says this skill must not be used for wallet balance/send/history and instead points users to a separate wallet skill. However, the 'Suggest Next Steps' section tells users that after a safe tx-scan they should 'Check wallet balance,' which extends beyond the documented scope of this security-scanning skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.