bingx-agent

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The BingX Agent skill presents a coherent, read-only data-access tool that signs requests with user-provided credentials and communicates with official BingX open API endpoints. There is no evidence of download/executable binaries, hardcoded credentials, or data exfiltration beyond the intended API data. The primary security considerations revolve around safe handling of user-provided API keys (avoid logging, storage, or leakage) and ensuring the agent does not inadvertently share credentials. Overall, the footprint is Benign with MEDIUM-low risk due to potential credential exposure in logs if misconfigured.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/BingX-API%2Fapi-ai-skills%2Fbingx-agent%2F@af1b3d780676c1e924fc98cfa035980bfc052b84