bingx-copytrade-swap

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill generates code to interact with the BingX API via HTTPS. It includes a validateParams function that explicitly checks for and rejects forbidden characters such as &, =, ?, #, and newlines to prevent parameter injection.
  • [DATA_EXFILTRATION]: All network operations are directed to legitimate vendor domains (open-api.bingx.com and open-api.bingx.pro). The authentication implementation uses standard HMAC SHA256 signing of request parameters.
  • [PROMPT_INJECTION]: The Agent Interaction Rules include strict instructions to extract structured values rather than copying raw user text and to validate all inputs against specific patterns (regex/enums).
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests data from external API responses, it includes robust boundary markers and validation logic. The capability is limited to authenticated API calls, and the instructions require the agent to ask for explicit CONFIRM before executing any state-changing operations on the production environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:57 PM
Security Audit — agent-trust-hub — bingx-copytrade-swap