okx-wallet-portfolio

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose and data flows are mostly coherent for portfolio lookup, and the installer is same-org, tag-pinned, and checksum-verified. However, it still relies on installing and running an external CLI/binary that may receive wallet data and optional personal API credentials, which is a disproportionate trust requirement compared with a simple read-only balance skill and creates notable supply-chain and credential-forwarding risk.

Confidence: 84%Severity: 80%
Audit Metadata
Analyzed At
Mar 14, 2026, 08:06 AM
Package URL
pkg:socket/skills-sh/okx%2Fonchainos-skills%2Fokx-wallet-portfolio%2F@9e3182242037c9d00c0de690cf26e1043a43c889