bingx-copytrade-spot
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill implements legitimate functionality for interacting with the BingX financial API.
- Authentication logic utilizes standard HMAC-SHA256 signing of request parameters, preventing credential exposure in transit.
- The skill includes safety guardrails by instructing the AI agent to require a 'CONFIRM' message from the user before executing sell orders on live production environments.
- No evidence of prompt injection, code obfuscation, or persistence mechanisms was found.
- [EXTERNAL_DOWNLOADS]: The skill makes requests to external API endpoints.
- Evidence:
https://open-api.bingx.com,https://open-api.bingx.pro,https://open-api-vst.bingx.com, andhttps://open-api-vst.bingx.pro. - Context: These are verified official API domains owned by the vendor (BingX), used for legitimate trade execution and data retrieval.
Audit Metadata