bitget-wallet
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The scripts
order_make_sign_send.pyandsocial_order_make_sign_send.pyutilizeimportlib.import_moduleto load the localbitget-wallet-agent-api.pyscript. This is used to handle the hyphenated filename which is incompatible with standard import statements. While the targets are local, dynamic loading of executable content is a monitored pattern. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the Bitget API (
copenapi.bgwapi.io), such as token narratives, social descriptions, and AI-generated market summaries, which are then presented to the agent. - Ingestion points: External API responses parsed in
scripts/bitget-wallet-agent-api.py. - Boundary markers: There are no explicit instructions to wrap these external text fields in delimiters to prevent the agent from following embedded instructions.
- Capability inventory: The skill has network access via the
requestslibrary and file system write access for temporary key management. - Sanitization: The skill relies on standard JSON decoding without specific sanitization for natural language instructions embedded within the data.
Audit Metadata