bingx-copytrade-spot
Warn
Audited by Snyk on Mar 11, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed for trading on BingX Copy Trade Spot. It includes authenticated, HMAC-SHA256 signed endpoints and a POST endpoint (/openApi/copyTrading/v1/spot/trader/sellOrder) whose purpose is to sell spot assets based on a buy order. The docs provide concrete code to sign requests and execute the sell operation, and the Agent Interaction Rules describe executing the sell in production (with a CONFIRM step). This is a specific, write-capable financial operation that executes trades (moves funds/positions), not a generic tool, so it grants direct financial execution authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata