okx-cex-trade

Pass

Audited by Gen Agent Trust Hub on Apr 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @okx_ai/okx-trade-cli package from the npm registry. This is an official vendor resource from the author 'okx' used to provide the core trading functionality.\n- [COMMAND_EXECUTION]: The skill executes authenticated trading operations using the okx CLI. These commands enable placing, amending, and canceling orders across spot, swap, futures, and options markets as requested by the user.\n- [DATA_EXPOSURE]: The skill manages sensitive API credentials required for exchange access. The documentation correctly identifies ~/.okx/config.toml as the storage location and provides explicit instructions for users to manage these credentials locally rather than exposing them in the conversation history.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it reads external data from the exchange API (such as order status and market details) and has the capability to perform financial transactions. This behavior is a functional requirement for the trading use case and no malicious instructions or bypass attempts were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 28, 2026, 10:05 AM