binance-trading-signal
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
@binance/agentic-walletpackage from the official NPM registry to provide thebawCLI functionality. This is a vendor-owned package consistent with the skill's authorship. - [COMMAND_EXECUTION]: The skill instructs the agent to execute
baw signalcommands and a local Node.js scriptscripts/cli.mjsto perform trading operations, backtesting, and signal retrieval. - [DATA_EXFILTRATION]: The helper script
scripts/cli.mjsperforms network operations, specifically sending POST requests toweb3.binance.com. These operations are directed to the vendor's official infrastructure and are required for the skill's primary purpose. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external trading signals and token information, creating a potential surface for indirect injection if that data were to contain malicious instructions.
- Ingestion points: External trading signal data from the Binance API and token metadata retrieved via the
binance-web3-query-token-infoskill. - Boundary markers: None explicitly defined in the provided instructions for separating untrusted signal content.
- Capability inventory: Network access via vendor tools, local command execution of specific scripts, and potential calls to other tools in the agent's environment.
- Sanitization: The skill uses structured JSON for command arguments and output parsing, reducing the risk of accidental instruction execution.
Audit Metadata