bingx-copytrade-spot
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and displays external data from BingX API endpoints (trading overview, profit history, and order details), creating a surface for potential indirect instructions.
- Ingestion points: Data is retrieved from various BingX API endpoints through the
fetchSignedfunction implemented inSKILL.md. - Boundary markers: The instructions do not specify the use of delimiters or boundary markers to isolate API-returned data from the agent's internal reasoning or system instructions.
- Capability inventory: The skill possesses the capability to execute sell orders through the
POST /openApi/copyTrading/v1/spot/trader/sellOrderendpoint defined inSKILL.mdandapi-reference.md. - Sanitization: The skill employs a
validateParamsfunction inSKILL.mdthat sanitizes user input by rejecting characters commonly used in URL manipulation or injection, such as&,=,?, and#.
Audit Metadata