bingx-copytrade-spot

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill implements legitimate functionality for interacting with the BingX financial API.
  • Authentication logic utilizes standard HMAC-SHA256 signing of request parameters, preventing credential exposure in transit.
  • The skill includes safety guardrails by instructing the AI agent to require a 'CONFIRM' message from the user before executing sell orders on live production environments.
  • No evidence of prompt injection, code obfuscation, or persistence mechanisms was found.
  • [EXTERNAL_DOWNLOADS]: The skill makes requests to external API endpoints.
  • Evidence: https://open-api.bingx.com, https://open-api.bingx.pro, https://open-api-vst.bingx.com, and https://open-api-vst.bingx.pro.
  • Context: These are verified official API domains owned by the vendor (BingX), used for legitimate trade execution and data retrieval.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 05:35 PM