Audit History
okx-dex - 2 audits
Version comparison
Capability and finding changes across audited versions, newest first.
Jul 21, 2026, 04:12 AM
Static detections are predominantly documentation false positives: inline code, placeholder credentials, fixed file references, and illustrative URLs. However, the shared preflight procedure authorizes arbitrary non-null CLI action data, including forced upgrades, so it creates a critical trust-boundary failure.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (15)
π Filesystem access (40)
π Env variables (30)
Jul 10, 2026, 12:24 AM
Most static findings are markdown formatting, placeholder credential examples, official OKX URLs, and fixed workflow hint paths. Confirmed risks are limited to parent-directory shared-file references, a remote installer fallback, and payment-default persistence that needs clear consent. No prompt injection attempt was found in the reviewed files.
Confirmed security concerns (2)
Capability review items (2)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.