Skills okx-guide
๐Ÿ“ฆ

okx-guide

v4.2.1 Content revision r1 Critical ๐Ÿ“ Filesystem access๐ŸŒ Network accessโš™๏ธ External commands๐Ÿ”‘ Env variables

Navigate Onchain OS and OKX.AI Onboarding

New users need help choosing the right Onchain OS path without exposing wallet secrets. This skill routes onboarding, OKX.AI, and support requests through guided flows.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "okx-guide" from https://skillstore.io/skills/internet-court-okx-guide.md and its manifest at https://skillstore.io/api/skills/internet-court-okx-guide/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.

Your Agent should still show its plan and request any confirmation required by the security policy.

Agent-readable resources

Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.

Test it

Using "okx-guide". What can I do with Onchain OS?

Expected outcome:

A localized welcome menu with an OKX.AI highlight, available workflow options, and a trading caution disclaimer.

Using "okx-guide". How do I use OKX.AI?

Expected outcome:

A role selection flow that explains User, ASP, and Evaluator paths, then waits for a role choice.

Using "okx-guide". I need customer support.

Expected outcome:

A short Help Center walkthrough that explains how to open support chat on the OKX.AI website.

Security Audit

Critical
v2 โ€ข 7/19/2026 Open versioned report

Most URL, secret-name, and backtick detections are documentation-only false positives. However, the skill obeys arbitrary preflight output and follows files outside its audited directory. It also loads hidden home workflows and can trigger plugin installation, creating critical supply-chain risk.

9
Files scanned
756
Lines analyzed
17
Review items
0
False positives ignored

Confirmed security concerns (2)

Critical
Untrusted Preflight Output Controls Agent Actions
The skill runs onchainos preflight and requires the agent to do exactly what data.action says. It also downloads and runs an installer when missing.
The mandatory text explicitly delegates agent control to command output and bootstraps executable installation. No action allowlist or user approval is required.
High
Automatic Third-Party Plugin Installation Route
Selecting Polymarket invokes another skill that routes to or installs polymarket-plugin. The installation occurs through an unaudited dependency path.
The routing table explicitly states that the invoked skill installs the plugin. This report does not include that plugin or an approval requirement.
Capability review items (17)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

High
Path traversal sequence
- `loggedIn: false` โ†’ user is not logged in. Do **not** query identity. Hand off to the existing wal
The flow loads ../../okx-agentic-wallet/SKILL.md outside the audited skill directory and follows its login instructions. That external content is not covered by this audit.
High
Hidden file in home directory
- If the user came from picking the **Daily brief** option (option `4` in Variant A / option `3` in
The instruction loads and follows a hidden home-directory workflow after login. A modified local workflow can provide unreviewed agent instructions.
High
Hidden file in home directory
- If the user came from picking any other **workflow pick** while logged out: automatically load the
The instruction dynamically loads a corresponding workflow from ~/.onchainos and follows it. The target content is outside the audited package.
High
Hidden file access
- If the user came from picking the **Daily brief** option (option `4` in Variant A / option `3` in
The agent is explicitly told to access and follow hidden local workflow content. This creates an unreviewed instruction boundary.
High
Hidden file access
- If the user came from picking any other **workflow pick** while logged out: automatically load the
The workflow path is in a hidden home directory and its content is followed automatically. No integrity check or confirmation is required.
High
Path traversal sequence
- **Status column** โ€” read the agent's `status` field and map it per [`../../okx-ai/references/ident
The flow reads status rules from ../../okx-ai outside the audited skill directory. Changes in that external file can alter agent behavior.
High
Path traversal sequence
Each "not registered yet" line on the home invites the user to register that role. If the user repli
The agent loads an external identity registration playbook and follows it to completion. That unaudited dependency can initiate consequential registration actions.
High
Path traversal sequence
| `1` (User) | `Registering your User identity, hang tight... โณ` | [`../../okx-ai/references/identit
Selecting User loads and follows an identity registration file outside the audited directory. The external playbook can perform consequential actions.
High
Path traversal sequence
| `2` (ASP) | `Registering your ASP identity, hang tight... โณ` | [`../../okx-ai/references/identity-
Selecting ASP loads and follows an identity registration file outside the audited directory. Its instructions are not reviewed in this report.
High
Path traversal sequence
| `3` (Evaluator) | `Registering your Evaluator identity, hang tight... โณ` | [`../../okx-ai/referenc
Selecting Evaluator loads an external registration flow that can continue into staking. This consequential dependency is outside the audited package.
High
Hidden file in home directory
| `3` | B | โ˜• Daily on-chain brief | **Yes** (logged-out โ†’ Login Method Choice โ†’ resume) | `~/.oncha
The menu routes a selection to a hidden daily-brief workflow in the home directory. That target is outside this audited skill.
High
Hidden file in home directory
| `4` | A | โ˜• Daily on-chain brief | **Yes** (logged-out โ†’ Login Method Choice โ†’ resume) | `~/.oncha
The alternate menu variant routes to the same hidden home workflow. Its content can change independently of this package.
High
Hidden file in home directory
- **Logged-in user**: load `~/.onchainos/workflows/daily-brief.md` directly and follow it.
Logged-in users cause the agent to load and follow ~/.onchainos/workflows/daily-brief.md directly. No content validation or approval is required.
High
Hidden file access
| `3` | B | โ˜• Daily on-chain brief | **Yes** (logged-out โ†’ Login Method Choice โ†’ resume) | `~/.oncha
This routing target accesses hidden local workflow content. The selected file is not part of the audited package.
High
Hidden file access
| `4` | A | โ˜• Daily on-chain brief | **Yes** (logged-out โ†’ Login Method Choice โ†’ resume) | `~/.oncha
This alternate menu path accesses the same hidden workflow. The agent later follows its unaudited instructions.
High
Hidden file access
- **Logged-in user**: load `~/.onchainos/workflows/daily-brief.md` directly and follow it.
The instruction explicitly reads and follows a hidden local Markdown file. A compromised workflow can control subsequent agent actions.
High
Path traversal sequence
**MUST**: Run the shared preflight **only for the onboarding flow** (ยง1 โ†’ `references/how-to-play.md
The mandatory preflight first reads ../okx-agentic-wallet/_shared/preflight.md outside this skill. That external file can change the instructions executed during onboarding.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/internet-court-okx-guide/audits/2?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/internet-court-okx-guide/security.svg)](https://skillstore.io/skills/internet-court-okx-guide?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/internet-court-okx-guide?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/internet-court-okx-guide/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/internet-court-okx-guide.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

internet-court. (2026). okx-guide security audit report (audit version 2) [Author version 4.2.1]. Skillstore. https://skillstore.io/skills/internet-court-okx-guide/audits/2

BibTeX citation

@techreport{internet-court-internet-court-okx-guide-2026, author = {internet-court}, title = {okx-guide security audit report (audit version 2)}, institution = {Skillstore}, year = {2026}, number = {2}, url = {https://skillstore.io/skills/internet-court-okx-guide/audits/2}, note = {Author version 4.2.1} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "okx-guide security audit report (audit version 2)" version: "4.2.1" type: report authors: - name: "internet-court" date-released: "2026-07-19" url: "https://skillstore.io/skills/internet-court-okx-guide/audits/2" identifiers: - type: other value: "skillstore:internet-court-okx-guide:audit:2" description: "Skillstore immutable audit report identifier"

Compare variants

2 installable variants

Each author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.

Why this variant is first

Higher Skillstore usage
internet-court Recommended Current

internet-court-okx-guide

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 5
Updated

2026-08-21

okx-okx-guide

Skillstore Score 38
Evidence Confidence Medium
Skillstore usage 1
Updated

2026-08-21

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
100
Maintainability
85
Content
65
Community
100
Spec Compliance

What You Can Build

Start With Onchain OS

A new wallet user gets a clear menu for OKX.AI, DeFi yield, Polymarket, or daily market briefs.

Choose an OKX.AI Role

An agent economy participant learns whether to register as a User, ASP, or Evaluator.

Find Support Fast

A user with a complaint or bug report receives the OKX.AI Help Center steps.

Try These Prompts

Get Started
I am new to Onchain OS. Show me where to start.
Understand OKX.AI
Explain what OKX.AI is and help me choose the right role.
Resume After Login
I picked the daily brief before logging in. Continue from that choice after login.
Review Agent Tasks
I already have an OKX.AI identity. Show my home view and help me check an Agent task.

Best Practices

  • Use it for onboarding, OKX.AI role guidance, or support routing requests.
  • Complete wallet login locally and never paste credentials into the conversation.
  • Follow the displayed menu numbers because choices can change by region and login state.

Avoid

  • Do not use it for swaps, token transfers, or direct on-chain trade execution.
  • Do not paste API keys, secret keys, passphrases, or wallet recovery data.
  • Do not ask it to bypass geoblocked or unavailable menu options.

Frequently Asked Questions

What does this skill do?
It guides users through Onchain OS onboarding, OKX.AI role paths, wallet login choices, and support routing.
Does it make on-chain transactions?
No. It routes and explains flows. Other skills handle transaction-specific actions when appropriate.
Can I paste API keys into chat?
No. Set credentials locally and rotate any secret that was pasted into a conversation.
Does it support Claude, Codex, and Claude Code?
Yes. The report lists compatibility with Claude, Codex, and Claude Code.
Why do menu numbers change?
The visible options depend on login state and availability checks. Reply using the menu currently shown.
Can it help me contact OKX.AI support?
Yes. It provides the Help Center link and steps to start support chat.

Developer Details

License

MIT

Author version

v4.2.1

Skillstore revision

r1

Ref

3f6e026a3363e0954ede7bef0cfe88d4475de137

Maintenance freshness

7/18/2026

Usage

1 downloads ยท 0 views

File structure

๐Ÿ“ _shared/

๐Ÿ“„ preflight.md

๐Ÿ“ references/

๐Ÿ“„ ai-guide.md

๐Ÿ“„ ai-support.md

๐Ÿ“„ how-to-play.md

๐Ÿ“„ intro.md

๐Ÿ“„ registered-home.md

๐Ÿ“„ unregistered-role-selection.md

๐Ÿ“„ welcome.md

๐Ÿ“„ SKILL.md

More from internet-court

View all
View all