bingx-spot-market

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill performs network requests to open-api.bingx.com and open-api.bingx.pro to retrieve market data. These are legitimate domains for the BingX exchange and align with the skill's stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses, which constitutes an ingestion surface.
  • Ingestion points: JSON responses from BingX API endpoints processed in the fetchSpotMarket function within SKILL.md.
  • Boundary markers: Not explicitly defined for the API output, though the skill provides structured guidance for the agent's interaction.
  • Capability inventory: The skill only performs network read operations via fetch. There are no file system write or command execution capabilities defined.
  • Sanitization: The skill mandates strict input validation rules, including regex checks for symbols and rejection of control characters like &, =, ?, #, and newlines.
  • [COMMAND_EXECUTION]: The provided TypeScript helper function uses the standard fetch API for network communication. There is no evidence of unsafe execution patterns such as eval(), exec(), or subprocess spawning.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:57 PM
Security Audit — agent-trust-hub — bingx-spot-market