okx-x402-payment

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill playbooks orchestrate interaction with the onchainos CLI tool for wallet management, authentication, and payment signing. These commands are consistent with the vendor's intended functionality for managing on-chain payments.- [DATA_EXPOSURE]: The x402 protocol playbook provides a local signing fallback that involves checking for a private key in the ~/.onchainos/.env configuration file. This operation is gated by explicit user selection of the local signing method and is presented as a secondary option to the recommended TEE-based signing.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external HTTP 402 response headers (WWW-Authenticate, PAYMENT-REQUIRED) and response bodies. Ingestion points: HTTP response headers and bodies (SKILL.md, protocols/mpp.md, protocols/x402.md). Boundary markers: No explicit markers for raw response data. Capability inventory: Execution of onchainos CLI commands for wallet login, status checks, and transaction signing. Sanitization: The skill implements a 'MANDATORY STOP' rule that requires the agent to display all decoded transaction details (amount, recipient, token, network) and wait for explicit user verification before proceeding with any tool calls or signing operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 02:54 PM