okx-cex-earn
Audited by Socket on Sep 15, 2026
2 alerts found:
Securityx2BENIGN in purpose alignment and data flow: it appears to be an official OKX skill using the official local CLI and first-party auth flow, with no clear credential exfiltration or malicious install path. However, it is HIGH security risk because it grants an AI agent live financial transaction capability on a crypto exchange, includes transitive skill loading for re-auth, and instructs silent use of live mode.
No malware or intentional supply-chain attack is evident. This is a readable operational guide for live OKX financial workflows. The principal concern is elevated financial-impact risk: commands can execute purchases, redemptions, transfers, and auto-earn changes, and the DCD workflow lacks a final explicit confirmation. Use least-privilege API permissions, require confirmation immediately before every write operation, and avoid unattended execution of live-account commands.