blofin-copy-trading
Pass
Audited by Gen Agent Trust Hub on Mar 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill documents standard interactions with the BloFin exchange API for copy trading functionality.
- [CREDENTIALS_UNSAFE]: The skill correctly identifies the need for 'BLOFIN_API_KEY', 'BLOFIN_API_SECRET', and 'BLOFIN_PASSPHRASE' as environment variables. No hardcoded secrets or sensitive values are present in the provided content.
- [COMMAND_EXECUTION]: While the skill mentions a requirement for 'node' in its metadata, there are no scripts or command-line executions provided within the skill itself that pose a risk.
- [DATA_EXFILTRATION]: All network operations (REST API and WebSocket) target the official BloFin infrastructure ('openapi.blofin.com'), which is consistent with the skill's stated purpose.
Audit Metadata