okx-cex-earn

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

BENIGN in purpose alignment and data flow: it appears to be an official OKX skill using the official local CLI and first-party auth flow, with no clear credential exfiltration or malicious install path. However, it is HIGH security risk because it grants an AI agent live financial transaction capability on a crypto exchange, includes transitive skill loading for re-auth, and instructs silent use of live mode.

Confidence: 91%Severity: 74%
SecurityMEDIUM
references/workflows.md

No malware or intentional supply-chain attack is evident. This is a readable operational guide for live OKX financial workflows. The principal concern is elevated financial-impact risk: commands can execute purchases, redemptions, transfers, and auto-earn changes, and the DCD workflow lacks a final explicit confirmation. Use least-privilege API permissions, require confirmation immediately before every write operation, and avoid unattended execution of live-account commands.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 15, 2026, 08:40 AM
Package URL
pkg:socket/skills-sh/okx%2Fagent-skills%2Fokx-cex-earn%2F@73277a4f253c17f758accfb2afe248ef893f20fadb277bb33ef9f9209ece1a38
Security Audit — socket — okx-cex-earn