okx-mcp-skill

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill is moderately aligned with its stated purpose and demonstrates appropriate auth and guardrails for high-impact actions. The most salient concerns are the presence of a shared demo key in documentation and the lack of explicit binary verification steps for any external tooling. These elevate security considerations beyond benign. The recommended posture is to treat as SUSPICIOUS (leaning toward BENIGN with careful review) and to enforce strict handling of demo credentials and explicit verification of any binaries before use in production. Final assessment: suspicious due to credential disclosure surface and reliance on external tooling without verifiable integrity checks, but not clearly malicious given the described workflow and safeguards.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/holon-run%2Fuxc%2Fokx-mcp-skill%2F@038ead5d4e9025b3fb889cc7a68df40f33a30458