okx-a2a-payment

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is purpose-aligned with A2A payments and uses a same-org CLI, so it is not malware. However, it is high risk because it enables autonomous financial actions and explicitly signs server-declared payment challenges without its own verification or confirmation gate; the main danger is unintended or manipulated payment authorization via the upstream trust boundary.

Confidence: 91%Severity: 82%
Audit Metadata
Analyzed At
Apr 29, 2026, 11:53 AM
Package URL
pkg:socket/skills-sh/okx%2Fonchainos-skills%2Fokx-a2a-payment%2F@7df7ad6eaeb952f65a509b8b50c57c38015b7365