okx-cex-portfolio

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is conceptually coherent: it serves as a portfolio/account management CLI for OKX, with clearly defined read/write commands, credential handling, and profile isolation. Data flows are constrained to OKX API endpoints and local credential stores, aligning with the stated purpose. There are no evident malicious data-exfiltration patterns, unverifiable binaries, or deceptive behaviors. The footprint is proportionate to its described tasks, and credential handling is appropriately emphasized. Overall assessment: BENIGN with MEDIUM-LOW security risk due to handling of API keys and potential logging exposure; no immediate red flags for supply-chain or data leakage beyond standard operational risks.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:58 AM
Package URL
pkg:socket/skills-sh/okx%2Fagent-skills%2Fokx-cex-portfolio%2F@596b1a20b07998422515545037f1628d9198c5cc