bingx-copytrade-swap
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill generates code to interact with the BingX API via HTTPS. It includes a
validateParamsfunction that explicitly checks for and rejects forbidden characters such as&,=,?,#, and newlines to prevent parameter injection. - [DATA_EXFILTRATION]: All network operations are directed to legitimate vendor domains (
open-api.bingx.comandopen-api.bingx.pro). The authentication implementation uses standard HMAC SHA256 signing of request parameters. - [PROMPT_INJECTION]: The
Agent Interaction Rulesinclude strict instructions to extract structured values rather than copying raw user text and to validate all inputs against specific patterns (regex/enums). - [INDIRECT_PROMPT_INJECTION]: While the skill ingests data from external API responses, it includes robust boundary markers and validation logic. The capability is limited to authenticated API calls, and the instructions require the agent to ask for explicit
CONFIRMbefore executing any state-changing operations on the production environment.
Audit Metadata