bingx-spot-market
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to
open-api.bingx.comandopen-api.bingx.proto retrieve market data. These are legitimate domains for the BingX exchange and align with the skill's stated purpose. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses, which constitutes an ingestion surface.
- Ingestion points: JSON responses from BingX API endpoints processed in the
fetchSpotMarketfunction withinSKILL.md. - Boundary markers: Not explicitly defined for the API output, though the skill provides structured guidance for the agent's interaction.
- Capability inventory: The skill only performs network read operations via
fetch. There are no file system write or command execution capabilities defined. - Sanitization: The skill mandates strict input validation rules, including regex checks for symbols and rejection of control characters like
&,=,?,#, and newlines. - [COMMAND_EXECUTION]: The provided TypeScript helper function uses the standard
fetchAPI for network communication. There is no evidence of unsafe execution patterns such aseval(),exec(), or subprocess spawning.
Audit Metadata