bingx-spot-trade

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided data for trading parameters which are subsequently used in API requests.
  • Ingestion points: User-provided trading parameters defined in SKILL.md, such as symbol, quantity, price, and stopPrice.
  • Boundary markers: The instructions explicitly command the agent to reject special characters (&, =, ?, #, or newline) and to avoid using raw user text in API calls.
  • Capability inventory: Network fetch operations to the BingX API for order placement and account management.
  • Sanitization: The skill mandates strict parameter validation, including regex checks for symbols (^[A-Z0-9]+-[A-Z]+$) and positive number checks for quantities and prices.
  • [EXTERNAL_DOWNLOADS]: The skill requires the json-bigint Node.js package to process high-precision numerical data returned by the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:57 PM
Security Audit — agent-trust-hub — bingx-spot-trade