bingx-spot-account
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill handles untrusted data from user inputs and external API responses.
- Ingestion points: User-supplied parameters (symbol, amount, etc.) are processed in
SKILL.md, and structured API responses are ingested according toapi-reference.md. - Boundary markers: Interaction rules instruct the agent to extract structured data only and require a specific 'CONFIRM' keyword from the user for sensitive operations.
- Capability inventory: The skill performs authenticated network requests via
fetchand generates HMAC-SHA256 signatures inSKILL.md. - Sanitization: The
validateParamsfunction inSKILL.mdimplements a whitelist-style check that rejects any parameter containing forbidden characters (&,=,?,#,\r,\n) to prevent parameter tampering or injection.
Audit Metadata