bingx-spot-ws-market

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize real-time data from an external WebSocket stream.
  • Ingestion points: External data enters the agent context through the onmessage handler in the provided TypeScript helper in SKILL.md.
  • Boundary markers: The skill specifies critical interaction rules that strictly prohibit the agent from returning code, raw API calls, or scripts to the user, requiring natural-language responses only.
  • Capability inventory: The skill facilitates read-only WebSocket connections to market data; it does not utilize tools for file system modification, command execution, or privileged network requests.
  • Sanitization: Input parameters like trading symbols and k-line intervals are validated against specific regex patterns and enums to prevent injection into the WebSocket subscription request.
  • [EXTERNAL_DOWNLOADS]: The skill's implementation logic depends on the third-party pako package.
  • Evidence: The TypeScript code snippet in SKILL.md imports the pako library to perform GZIP decompression on the binary data received from the WebSocket.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:57 PM
Security Audit — agent-trust-hub — bingx-spot-ws-market