Latest Announcement
See all articlesHashKey Global Team
Hashkey Has Launched Agent Skills
Dear HashKey Clients,
We are proud to officially introduce HashKey Agent Skills, a suite of structured capability components designed for developers and AI Agents. Built upon HashKey’s existing API infrastructure, this project aims to empower clients with more efficient automated integration for account management, trade execution, fund operations, and market data retrieval—all while ensuring security, compliance, and auditability.
Agent Skills is positioned as a governance layer for capabilities and workflows; it does not constitute an independent trading entry point, nor does it bypass existing risk control systems. All operations involving assets, trading, transfers, and withdrawals are subject to explicit confirmation, whitelist restrictions, environment isolation, and audit logging to ensure end-to-end controllability.
I. Key Advantages
- Accelerated Integration Efficiency: Intent-driven logic simplifies complex interface calls, significantly boosting the speed of Agent integration into production workflows.
- Superior Security Defaults: Strictly follows a "Draft -> Explicit Confirmation -> Write Operation" single-client execution logic, ensuring every automated instruction undergoes human review.
- Multi-Site Consistency: Full support for all HashKey sites, providing clear and unified operational feedback.
- Reduced Operational Risk: Built-in validation for editing rules and 2FA processing, with a mandatory "Sandbox-First" control policy.
II. Functional Scope
The current release of Skills components covers the following categories:
- Account: Balance inquiry, account type identification, and internal transfers (with confirmation mechanisms).
- Trading: Spot and OTC trading (order placement, cancellation, and position control).
- Wallet: Deposit and withdrawal workflows (high-risk operations strictly controlled by access gates).
- Market Data: Order book, trade history, K-line (candlestick), tickers, and trading pair information (Read-only).
- Multi-Site Support: Compatibility across all HashKey sites, supporting prioritized validation in sandbox environments.
- Rapid Integration: Direct mapping of client intent to stable operational workflows.
III. Security and Compliance Mechanisms
Agent Skills strictly adheres to the existing API permission system; users must apply for API keys and configure corresponding permissions themselves. The following control policies are built-in at the runtime level:
- Operation Traceability: All "write" operations are recorded in auditable logs to ensure full transparency and accountability.
- Client Confirmation: High-risk actions require explicit confirmation from the client before execution to prevent unauthorized operations.
- Credential Management: API keys and sensitive credentials are prohibited from being stored directly within the code.
- Domain Restrictions: The Agent is restricted to requesting only HashKey-authorized API endpoints, with all unauthorized external network access strictly prohibited.
- Environment Isolation: A mandatory "Sandbox-First" principle is enforced. The system operates in a sandbox environment by default; switching to the production environment for live trading requires an explicit, multi-step confirmation process to prevent accidental operations due to configuration errors.
IV. Installation and Usage
- Agent Skills can be integrated into mainstream Agent environments, including Cursor, Codex, and custom directories. Clients can deploy quickly via installation scripts and select specific sites and environments.
- For detailed documentation, installation guides, and full risk disclosures, please visit: https://docs.hashkey.com/glb/en/index.html#agent-skills-overview
V. Risk Disclosure
HashKey Agent Skills serves as a tool and workflow auxiliary layer and does not constitute investment, trading, or any form of advice. Clients bear full responsibility for their decisions, API key management, and all operations. The digital asset market involves high risk and volatility; leverage and derivative trading may lead to rapid losses exceeding expectations. AI-generated content may be inaccurate or delayed and should not be used as the sole basis for decision-making. Please test thoroughly in a sandbox environment before use and strictly follow the principle of least privilege when configuring API keys.
Thank you for your continued support and trust in HashKey. We remain committed to providing a more efficient integration experience for our clients and developers under a secure and compliant framework.
HashKey Team
Apr 2026