PluginBench
Skill
Review
Audit score 70

okx-security

okx/onchainos-skills

Scan tokens, transactions, signatures, and approvals for security risks before executing on-chain operations.

What is okx-security?

okx-security provides pre-execution security scanning across tokens, DApps, transactions, signatures, and approvals. Use it to detect honeypots, phishing, malicious transactions, and risky token authorizations before you trade, swap, or sign anything on-chain.

  • Token risk scanning with honeypot and tax detection across all chains
  • DApp and URL phishing detection to identify scam websites
  • Transaction pre-execution security analysis for EVM and Solana
  • Message signature safety checks for EIP-712 and personal_sign requests
  • Token approval and Permit2 authorization monitoring with revocation support

How to install okx-security

npx skills add https://github.com/okx/onchainos-skills --skill okx-security
Claude Code
Cursor
Windsurf
Cline

How to use okx-security

  1. 1.Run `onchainos security token-scan <token-address> [chain]` to analyze token risk and honeypot status
  2. 2.Run `onchainos security dapp-scan <url>` to check if a domain is a known phishing site
  3. 3.Run `onchainos security tx-scan <tx-hash-or-data> [chain]` to pre-execute and detect malicious transactions
  4. 4.Run `onchainos security sig-scan <message> [signature-type]` to validate message signatures before signing
  5. 5.Run `onchainos security approvals [address] [chain]` to list and manage token authorizations

Use cases

Good for
  • Check if a token is safe before buying or swapping it
  • Verify a DApp URL is legitimate before connecting your wallet
  • Scan a transaction before execution to detect malicious contract interactions
  • Validate a signing request to ensure it won't drain your wallet
  • Review and revoke risky token approvals that expose your assets
Who it's for
  • DeFi traders evaluating new tokens
  • Users verifying DApp legitimacy before connecting
  • Anyone signing transactions or messages on-chain
  • Wallet security-conscious users managing token approvals

okx-security FAQ

What happens if a security scan detects high risk?

For transactions and signatures, high-risk (`block`) results prevent execution and recommend cancellation. For tokens, CRITICAL risk blocks buys but allows sells. MEDIUM/HIGH risk shows warnings and may require explicit user confirmation depending on operation type.

What if a security scan fails due to network error?

The agent reports the error and asks whether to retry or proceed without scan results. Proceeding without a completed scan displays a warning that verification could not be completed.

Does this skill require wallet login?

No. Security commands work with any address and do not require wallet authentication.

Which chains are supported?

Token-scan supports all chains. Transaction-scan supports EVM chains (Ethereum, BSC, Polygon, Arbitrum, Base, etc.) and Solana. Signature and approval scanning are EVM-only.

Can I revoke token approvals with this skill?

Yes. The `approvals` command lets you query and revoke ERC-20 and Permit2 authorizations to reduce exposure to malicious contracts.

Full instructions (SKILL.md)

Source of truth, from okx/onchainos-skills.


name: okx-security description: "Use this skill for security scanning: check transaction safety, is this transaction safe, pre-execution check, security scan, token risk scanning, honeypot detection, DApp/URL phishing detection, message signature safety, malicious transaction detection, approval safety checks, token approval management. Triggers: 'is this token safe', 'check token security', 'honeypot check', 'scan this tx', 'scan this swap tx', 'tx risk check', 'is this URL a scam', 'check if this dapp is safe', 'phishing site check', 'is this signature safe', 'check this signing request', 'check my approvals', 'show risky approvals', 'revoke approval', 'check if this approve is safe', token authorization, ERC20 allowance, Permit2. Covers token-scan, dapp-scan, tx-scan (EVM+Solana pre-execution), sig-scan (EIP-712/personal_sign), approvals (ERC-20/Permit2). Chinese: 安全扫描, 代币安全, 蜜罐检测, 貔貅盘, 钓鱼网站, 交易安全, 签名安全, 代币风险, 授权管理, 授权查询, 风险授权, 代币授权. Do NOT use for wallet balance/send/history — use okx-agentic-wallet." license: MIT metadata: author: okx version: "4.0.0" homepage: "https://web3.okx.com"

Onchain OS Security

5 commands for token risk analysis, DApp phishing detection, transaction pre-execution security, signature safety, and approval management.

Pre-flight Checks

Read ../okx-agentic-wallet/_shared/preflight.md. If that file does not exist, read _shared/preflight.md instead.

Fail-safe Principle (CRITICAL)

Scan completed — risk detected

If a security scan completes successfully and returns action: "block" or action: "warn", follow the Risk Action Priority Rule below. The Agent MUST NOT override risk verdicts.

Scan failed — infrastructure error

If a security scan fails to complete (network error, API timeout, rate limiting, malformed response), the Agent MUST:

  • Report the error clearly to the user.
  • Ask the user whether to retry the scan or proceed without scan results.
  • If the user chooses to proceed, display a warning:

    "⚠️ Security scan could not be completed. Proceeding without verification — please ensure you trust this operation."

  • Log the skipped scan for auditability.

A security scan that fails to complete is NOT a "pass". Always inform the user and let them make an explicit decision.

Risk Action Priority Rule

tx-scan / sig-scan (transaction & signature scanning)

block > warn > safe (empty). The top-level action field reflects the highest priority from riskItemDetail.

action valueRisk LevelAgent Behavior
(empty/null)Low riskSafe to proceed
warnMedium riskShow risk details, ask for explicit user confirmation
blockHigh riskDo NOT proceed, show risk details, recommend cancel
  • Risk scan result is still valid even if simulation fails (simulator.revertReason may contain the revert reason).
  • If warnings field is populated, the scan completed but some data may be incomplete. Still present available risk information.
  • An empty/null action in a successful API response means "no risk detected". But if the API call failed, the absence of action does NOT mean safe — apply the fail-safe principle.

token-scan (token risk label scanning)

Token-scan returns a riskLevel field (CRITICAL, HIGH, MEDIUM, LOW) that represents the overall token risk, computed server-side from all boolean labels, tax thresholds, and additional signals (off-chain intelligence, ML models). The Agent uses this field directly and applies different actions for buy vs. sell operations.

riskLevelBuy ActionSell Action
CRITICALblock — refuse to buywarn — display risk, allow sell
HIGHwarn + pause — require explicit yes/nowarn — display risk, allow sell
MEDIUMwarn — info notice, continuewarn — info notice, continue
LOWsafe — proceedsafe — proceed

Full label catalog, tax threshold rules, and display format are defined in references/risk-token-detection.md. Always load that reference before executing token-scan.

Key principles:

  • riskLevel is authoritative: The API returns the overall risk level server-side. The Agent reads riskLevel directly — no client-side computation from individual labels is needed.
  • Buy is stricter than sell: CRITICAL blocks buy but only warns on sell (to allow stop-loss exit).
  • HIGH buy requires explicit user confirmation (yes/no) — do not auto-continue.
  • Individual label levels are not displayed to the user — only the overall riskLevel is shown, with triggered labels listed without level prefixes.
  • If isChainSupported: false, skip detection with a warning; do not block.
  • If API fails, warn but do not block. In swap context, token-scan failures auto-continue with a warning to avoid blocking time-sensitive trades — this overrides the general fail-safe's ask-user behavior.

Security commands do not require wallet login. They work with any address.

Chain Name Support

The CLI accepts human-readable chain names and resolves them automatically.

ChainNamechainIndex
XLayerxlayer196
Ethereumethereum or eth1
Solanasolana or sol501
BSCbsc or bnb56
Polygonpolygon or matic137
Arbitrumarbitrum or arb42161
Basebase8453
Avalancheavalanche or avax43114
Optimismoptimism or op10
zkSync Erazksync324
Linealinea59144
Scrollscroll534352

Address format note: EVM addresses (0x...) work across Ethereum/BSC/Polygon/Arbitrum/Base etc. Solana addresses (Base58) and Bitcoin addresses (UTXO) have different formats. Do NOT mix formats across chain types.

Related Workflows

When one of the following commands is used, show the related workflow hint after displaying results:

CommandWorkflowFile
security token-scanNew Token Screening~/.onchainos/workflows/new-token-screening.md
security token-scanSmart Money Signals~/.onchainos/workflows/smart-money-signals.md
security token-scanToken Research~/.onchainos/workflows/token-research.md
security token-scanWallet Monitor~/.onchainos/workflows/wallet-monitor.md

Hint format: "You can also try out our [workflow name] workflow for more comprehensive results. Would you like to try it?"

Command Index

#CommandDescription
1onchainos security token-scanToken risk / honeypot detection (all chains)
2onchainos security dapp-scanDApp / URL phishing detection (chain-agnostic)
3onchainos security tx-scanTransaction pre-execution security (EVM + Solana)
4onchainos security sig-scanMessage signature security (EVM only)
5onchainos security approvalsToken approval / Permit2 authorization query (EVM only)

Reference Loading Rules (MANDATORY)

Before executing ANY security command, you MUST read the corresponding reference document from skills/okx-security/references/. Do NOT rely on prior knowledge — always load the reference first.

User intentRead this file FIRST
Token safety, honeypot, is this token safe, 代币安全, 蜜罐检测, 貔貅盘references/risk-token-detection.md
DApp/URL phishing, is this site safe, 钓鱼网站references/risk-domain-detection.md
Transaction safety, tx pre-execution, signature safety, approve safety, 交易安全, 签名安全references/risk-transaction-detection.md
Approvals, allowance, Permit2, revoke, 授权管理, 授权查询, 风险授权references/risk-approval-monitoring.md

When a workflow involves multiple commands (e.g., token-scan then tx-scan), load each reference before executing that command.

Integration with Other Skills

Security scanning is often a prerequisite for other wallet operations:

  • Before wallet send with a contract token: run token-scan to verify token safety
  • Before wallet contract-call with approve calldata: run tx-scan to check spender
  • Before interacting with any DApp URL: run dapp-scan
  • Before signing any EIP-712 message: run sig-scan

Use okx-agentic-wallet skill for the subsequent send/contract-call operations.