Back to skill

Security audit

mt5-trading-assistant

Security checks for vulnerabilities and agentic risk

Overview

This MT5 trading skill is purpose-aligned, but it ships reusable broker credentials and can place or close trades without strong user confirmation or risk controls.

Review carefully before installing. Do not run the included scripts as-is. Treat the embedded MT5 password as exposed, use a demo account only unless the code is changed, remove all hardcoded credentials, require explicit confirmation or dry-run mode before any trade or close action, and pin dependencies before using this in any real trading environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mt5_buy.py:24
Finding

Hardcoded MT5 Credentials Permit Unauthorized Account Access and Trading

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mt5_buy.py:81
Finding

Financially Consequential Orders Are Submitted Without Enforced Risk Controls

Content
View full analysis
2: price_arg = float(sys.argv[2]) if price_arg > 0: price = price_arg sl = None if len(sys.argv) > 3: sl_arg = float(sys.argv[3]) if sl_arg > 0: sl = sl_arg tp = None if len(sys.argv) > 4: tp_arg = float(sys.argv[4]) if tp_arg > 0: tp = tp_arg # 执行买入 success = buy_order(volume, price, sl, tp) ``` The configuration template advertises limits that the executable order paths do not read or enforce: ```python # 风险管理 "max_risk_per_trade": 0.02, # 单笔交易最大风险比例 (2%) "max_daily_loss": 0.10, # 单日最大亏损比例 (10%) ``` ### Technical Analysis The buy and sell scripts accept arbitrary floating-point volume, price, stop-loss, and take-profit values. They then construct a market-deal request and call `mt5.order_send()` without enforcing the advertised risk limits. The c ...[truncated 2369 chars]
Remediation
View remediation
1e-9: raise ValueError("Volume does not match the broker volume step") ``` 3. Require a stop loss by default and validate its direction: - Buy order: stop loss below entry and take profit above entry. - Sell order: stop loss above entry and take profit below entry. 4. Enforce the symbol's minimum stop-distance and price precision. 5. Calculate monetary loss at the stop price and reject orders exceeding `max_risk_per_trade`. 6. Calculate realized and unrealized daily loss and stop trading when `max_daily_loss` is reached. 7. Apply limits to aggregate exposure, not only to individual orders. 8. Estimate required margin using MT5 APIs and compare it against free margin with a safety buffer. 9. Call `mt5.order_check(request)` and reject the order unless the preflight result is explicitly successful. 10. Require explicit confirmation for production accounts and orders above a conservative threshold. 11. Implement a dry-run mode as the default and require a separate flag to permit live submission. 12. Add tests covering negative, zero, non-finite, oversized, incorrectly stepped, and unprotected orders. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Installation Instructions Use Unpinned Third-Party Dependencies

Content
View full analysis
Remediation
View remediation
\ --hash=sha256: ``` 5. Pin optional packages such as `pandas` and `numpy` in a separate optional requirements file. 6. Install dependencies in an isolated virtual environment rather than a shared interpreter. 7. Document the expected package index and avoid untrusted mirrors. 8. Review dependency release notes and artifacts before updating pinned versions. 9. Run dependency vulnerability and integrity scanning as part of the release process. 10. Avoid running package installation as an administrator unless strictly required. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents direct trade execution and bulk position-closing commands without a prominent, repeated warning that these actions may affect a live brokerage account and cause immediate, irreversible financial loss. Because the commands are simple and operationally ready, users may treat them as routine examples and execute them against real accounts without appreciating the risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script hardcodes live-looking MT5 account credentials directly in source code, including the account number, password, and server. Anyone with access to the file can reuse those credentials to access the trading account, place trades, exfiltrate account data, or cause financial loss; the surrounding comment warning does not meaningfully reduce the risk because the secret is still exposed at rest.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script embeds a real MT5 account number, password, and server directly in source code. Hardcoded broker credentials are highly sensitive because anyone with code access can reuse them to access the trading account, inspect balances/positions, and potentially place or influence trades depending on account permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script silently uses embedded MT5 credentials with no warning, consent flow, or explanation of sensitive account access. In the context of a broker login, this is dangerous because users or downstream maintainers may execute the script without realizing it authenticates to a live external financial service using privileged secrets.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script contains hardcoded MetaTrader5 account credentials and immediately uses them to authenticate to a live brokerage server. Embedding reusable trading credentials in code creates direct account-compromise risk: anyone with access to the file can log in, inspect account state, and perform trading actions without the account holder's consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Hardcoded login credentials are used silently, without any user-facing disclosure that the script will access a brokerage account. This prevents informed consent and makes covert account access possible if the skill is invoked by an unsuspecting user or automation framework.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code sends live trade-closing requests through mt5.order_send, allowing it to liquidate open positions on a brokerage account. In the context of an agent skill, this is a destructive financial action with real-world consequences, and there is no manifest-stated justification, approval boundary, or safety gate limiting when such orders may be executed.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The bulk close path can close all positions for a symbol, which is an irreversible and potentially loss-inducing action, yet it proceeds without explicit confirmation or a preview of affected trades. In an automation/skill context, lack of a confirmation barrier materially increases the chance of accidental or unauthorized liquidation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script submits a live sell order immediately once arguments are parsed, with no interactive confirmation, dry-run mode, account/environment validation, or explicit warning that real trading will occur. In the context of an automated trading script, this materially increases the risk of accidental or unintended execution, especially since the file also contains hardcoded credentials and targets a live broker session.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script contains hardcoded MetaTrader account credentials and uses them directly to authenticate to a live external service. Embedded secrets are easily exposed through source access, logs, backups, or redistribution of the skill, enabling unauthorized access to the trading account and any connected financial or personal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script silently uses embedded credentials to log into a trading account without any disclosure to the user that sensitive authentication material is present or being used. This reduces transparency and increases the chance that operators run the script unaware that it is authenticating against a real account, exposing them to account compromise and unintended access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script hardcodes and uses real MetaTrader 5 account credentials to authenticate against a broker server, which exposes sensitive secrets directly in source code and enables unauthorized account access by anyone who can read the file. In a test script, this is especially unjustified because it grants credentialed access to an external trading platform without any access controls, creating risk of account misuse, data exposure, or unauthorized trading activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Hardcoded trading credentials in plaintext are a direct secret exposure vulnerability, and the script provides no warning, consent flow, or protective disclosure before using them to log into an external service. This increases the chance that users unknowingly run code that accesses a broker account, while attackers or repository readers can immediately reuse the credentials.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The installation guide explicitly instructs users to place MT5 account passwords directly into script configuration, which contradicts the later security advice not to hardcode secrets. In a trading skill, this is especially dangerous because leaked credentials can enable unauthorized access to brokerage accounts and potentially direct financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide presents direct commands for buying, selling, and mass-closing positions close to normal usage instructions without prominent, immediate warnings or mandatory confirmation language. Because this skill operates on live trading accounts, the lack of strong safety framing materially increases the risk of user error leading to real financial loss.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed trigger keywords are very broad and overlap with ordinary discussion of trading, forex, and account monitoring, increasing the chance that the skill activates when the user did not intend to perform trading-related actions. In the context of a skill capable of executing trades and closing positions, accidental invocation can create unauthorized or unintended financial operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list is extremely broad and includes generic phrases like trading automation, execute trade, buy/sell orders, and account monitoring, which can cause the skill to activate for loosely related user requests. In a skill that can place or close live trades, overbroad activation increases the chance of unintended invocation and financially harmful actions.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 361)May include surrounding context.

"server": os.getenv("MT5_SERVER"), }

text
3. **Set file permissions**: `chmod 600 config.py`
4. **Add to .gitignore**: `echo "config.py" >> .gitignore`
5. **Regular password rotation**: Change passwords every 30-90 days

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill file contains natural-language guidance, comments, and safety notes exclusively in Chinese, which effectively forces a specific language for users and maintainers. Under the policy, language restrictions should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide directs users to enable MT5 auto-trading and later suggests running a buy-order script, but it does not place a prominent warning at the point of action that this can trigger real trades on funded accounts. In a trading assistant context, this omission increases the chance of accidental financial loss from unintended live execution, especially for inexperienced users following setup steps verbatim.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Docstrings and all user-facing output strings are in Chinese, which creates a language-specific experience with no opt-in or alternative locale support. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code prints that auto-trading is enabled and that the test passed without checking any MT5 terminal or account state to verify that claim. This can mislead operators into believing trading automation is active and healthy, causing unsafe operational decisions or masking misconfiguration during live trading.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Closing a specific ticket is still a live, irreversible trading operation that can realize gains or losses immediately, but the script performs it directly once invoked. Although narrower than bulk close, the absence of a confirmation prompt or secondary validation still creates meaningful risk of operator error or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script prints account balance, equity, free margin, leverage, open positions, ticket numbers, and profit/loss data directly to output without warning or masking. Such financial information is sensitive and may be exposed through terminal history, screenshots, shared logs, or agent output channels, creating confidentiality and operational security risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Although this file is presented as a snapshot/reporting script, it advertises executable buy, sell, and close-all trading commands, which expands the operational risk and can encourage unintended high-impact actions. In a skill context, surfacing such commands without safeguards, confirmations, or authorization checks makes accidental or unauthorized trading more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.