bingx-spot-account

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data from user inputs and external API responses.
  • Ingestion points: User-supplied parameters (symbol, amount, etc.) are processed in SKILL.md, and structured API responses are ingested according to api-reference.md.
  • Boundary markers: Interaction rules instruct the agent to extract structured data only and require a specific 'CONFIRM' keyword from the user for sensitive operations.
  • Capability inventory: The skill performs authenticated network requests via fetch and generates HMAC-SHA256 signatures in SKILL.md.
  • Sanitization: The validateParams function in SKILL.md implements a whitelist-style check that rejects any parameter containing forbidden characters (&, =, ?, #, \r, \n) to prevent parameter tampering or injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:57 PM
Security Audit — agent-trust-hub — bingx-spot-account