Sato Check · Package
@okx_ai/okx-trade-mcp
npm:@okx_ai/okx-trade-mcp · v1.4.8 · sha256:82fcc061d3cc · as of 2026-09-28
- Does it take your key? no evidence
- No private-key read found in what we read of its setup and published code — the limits say how much that was.
- No evidence line on file for this question yet.
- Does your key leave? no evidence
- Not yet run — we have not run this version with planted test keys.
- No evidence line on file for this question yet.
- Can it move funds on its own? no evidence
- Unknown — we could not read what it exposes.
- No evidence line on file for this question yet.
- What changed? no evidence
- First profile of this subject — nothing to compare yet.
- No evidence line on file for this question yet.
Is this your project? Respond →Dispute this reading
Hosts contacted
| Host | When | Role | Evidence |
|---|---|---|---|
| app.okx.com | code | vendor | traced |
| eea.okx.com | code | vendor | traced |
| my.okx.com | code | vendor | traced |
| registry.npmjs.org | code | registry | traced |
| tr.okx.com | code | vendor | traced |
| us.okx.com | code | vendor | traced |
| www.okx.com | code | vendor | traced |
Evidence (8 lines)
- tracedT-install-script2026-09-28
package.json runs postinstall: node scripts/postinstall.js || exit 0.
package.json
- tracedT-hosts2026-09-28
app.okx.com appears in shipped code (vendor).
dist/index.js
- tracedT-hosts2026-09-28
eea.okx.com appears in shipped code (vendor).
dist/index.js
- tracedT-hosts2026-09-28
my.okx.com appears in shipped code (vendor).
dist/index.js
- tracedT-hosts2026-09-28
registry.npmjs.org appears in shipped code (registry).
dist/index.js
- tracedT-hosts2026-09-28
tr.okx.com appears in shipped code (vendor).
dist/index.js
- tracedT-hosts2026-09-28
us.okx.com appears in shipped code (vendor).
dist/index.js
- tracedT-hosts2026-09-28
www.okx.com appears in shipped code (vendor).
dist/index.js
Limits
- The observed lane has not run on this version: not yet run on this version
- Traced analysis follows flows inside one module only; a key handed from one module to another is not followed.
- The observed lane has not run on this version.
- No tool inventory was available, so fund actions were not read.
A profile describes what we read and ran, with dates. It is not a safety rating, an audit or an endorsement, and "not found" is not "not there".
sato.custody/v1 · custody-1
Maintain this project? Respond to this reading
Loading sign-in…