okx
OKX OnChainOS: on-chain trading, analytics, security, DeFi across 20+ chains. Use when running OKX-routed on-chain ops (e.g. swap on Ethereum, scan token risk, track smart money, check wallet portfolio). Wallet: default to the user's Agent Wallet (via the `wallet` skill). Only use the OnchainOS TEE wallet (`onchainos wallet login <email>`) when the user explicitly asks for it.
Security Assessment
Detected risks:
About okx
This skill is a directory/catalogue entry that points to OKX's official onchainos-skills repository, exposing OKX OnChainOS — a suite of eight specialized sub-skills for on-chain trading, market analytics, smart-money signals, DeFi investing, wallet operations, security scanning, payments, agent identity, and crypto news across 20+ blockchains. The top-level file contains no logic of its own; it explains how sub-skills are fetched fresh from upstream on install and catalogues them by category (DEX market data, DApp discovery, agentic wallet, DeFi). Most sub-skills drive a single onchainos binary, downloaded on first use.
It documents two authentication paths. Path A calls OKX web3 endpoints directly through Starchild's sc-proxy for read-only data (roughly 80% of capabilities: prices, K-line, smart-money signals, token analytics, security checks, public-address portfolios), with platform credentials injected and HMAC-SHA256 signing, billed per request. Path B uses the onchainos CLI with the caller's own OKX Web3 API key/secret/passphrase for wallet operations, executable swaps, and payments — noting the CLI ships shared sandbox keys for evaluation only that must not be used with real assets, and explaining why the CLI's bundled TLS root store prevents it from being transparently proxied.
Target users are agents and developers running OKX-routed on-chain operations. The score sits below the benign threshold because the skill installs a binary via remote curl-piped-to-shell and PowerShell irm/iex one-liners, drives real wallet operations and on-chain transactions, and documents storing exchange API secrets in environment variables — legitimate official tooling, but higher-consequence and with a remote-code install pattern.
FAQ
Does this skill contain the actual OKX logic?
No. It is a directory page that points to OKX's official okx/onchainos-skills repository. Each of the eight sub-skills ships its own SKILL.md, reference docs, and trigger phrases upstream and is fetched fresh on install.
How is authentication handled?
Two paths: Path A calls OKX web3 endpoints through Starchild's sc-proxy for read-only data with no API key needed (platform credentials are injected and requests HMAC-signed, billed per request); Path B uses the onchainos CLI with your own OKX Web3 API key, secret, and passphrase for wallet ops, executable swaps, and payments.
Are the built-in API keys safe to use in production?
No. The CLI ships built-in sandbox keys that work out of the box but are shared, rate-limited, and for evaluation only. The skill explicitly says not to use them in production or with real assets, and to bring your own credentials for production.
How is the onchainos binary installed?
The binary is auto-downloaded on first use, or installed via a remote install script piped into a shell on macOS/Linux (or an irm/iex PowerShell one-liner on Windows). The installer auto-detects platform and verifies a SHA256 checksum.
Which wallet does it use by default?
It defaults to the user's platform Agent Wallet for signing and broadcasting, feeding unsigned DEX calldata to the wallet skill. The OnchainOS TEE wallet (onchainos wallet login) is used only when the user explicitly asks for it, and it does not import an existing OKX app/extension wallet.
Install okx
Quick Setup:
- Copy the skill folder to
.claude/skills/ - Claude will automatically detect and use the skill
Repository
starchild-ai-agent/official-skills