Security audit
preftrade AIO Quantitative Research Tools
Security checks for vulnerabilities and agentic risk
Overview
This is a documentation-only setup guide for a remote PREF research MCP service, with disclosed API-key and network use and no hidden local code.
Install only if you trust pref.trade with the research queries and tool arguments sent through the MCP. Store the PREF key as a secret, avoid printing it with echo in any logged agent session, and review the MCP capabilities before allowing sensitive or high-impact use.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
