Back to skill

Security audit

mql-compiler

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for compiling MQL files, but its install instructions execute mutable remote scripts, including an optional root-level path, without verification.

Install only if you trust the upstream GitHub repository and Docker image. Prefer downloading and reviewing the installer first, pinning to a specific commit or release, and avoiding the sudo/system-wide path unless you truly need it. Be aware that the tool keeps a Docker volume cache and deleting that volume can affect every user on the machine.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping network-fetched content directly into bash removes the review boundary and turns a documentation example into a one-step arbitrary command execution primitive. In the context of a user-invocable skill that may be followed by automation agents or users verbatim, this materially increases the risk of host compromise from upstream tampering.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

If mql-compiler is not on PATH, install it for the current user:

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mql-compiler/master/install.sh | bash

It lands in ~/.local/bin; if that is not on PATH, the installer prints the line to add. For system-wide installs, upgrades, uninstalling, custom installers and troubleshooting, see references/installation.md.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping remote content directly into bash is dangerous because it executes whatever the server returns without validation, review, or pinning. Although this variant runs as the user rather than root, it still enables arbitrary code execution and can lead to credential theft, backdoors, or further local compromise.

Content

Scanner excerpt · references/installation.md (reported line 10)May include surrounding context.

Per user, into ~/.local/bin:

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mql-compiler/master/install.sh | bash

System wide, into /usr/local/bin:

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Chaining a remote fetch directly into sudo bash combines two high-risk behaviors: unreviewed network content and privileged shell execution. If an attacker controls or alters the fetched script, they gain full root execution immediately, making this one of the most severe issues in the file.

Content

Scanner excerpt · references/installation.md (reported line 16)May include surrounding context.

System wide, into /usr/local/bin:

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mql-compiler/master/install.sh | sudo bash -s -- --system

| Option | Effect |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to download a remote script and pipe it directly into bash, which executes unreviewed code immediately with the user's privileges. If the upstream repository, transport path, or referenced branch is compromised, an attacker can achieve arbitrary code execution on the host during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation instructions fetch a remote script from GitHub and pipe it directly into bash/sudo bash, which removes the user's opportunity to inspect the script before execution. If the remote source, repository, branch, or network path is compromised, this yields arbitrary code execution, including root-level execution for the system-wide path.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/installation.md (reported line 16)May include surrounding context.

System wide, into /usr/local/bin:

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mql-compiler/master/install.sh | sudo bash -s -- --system

| Option | Effect |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/installation.md (reported line 47)May include surrounding context.

System wide, into /usr/local/bin:

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mql-compiler/master/install.sh | sudo bash -s -- --system

| Option | Effect |

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/installation.md (reported line 26)May include surrounding context.

md
| `--rolling` | Pin `psyb0t/mql-compiler:latest` instead of the newest release tag |
| `--uninstall` | Remove the command and the image it was pinned to; the toolchain volume stays |

The installer pins the newest GitHub release (for example `psyb0t/mql-compiler:v0.3.0`), pulls it, and writes the pin into the command file. There is no config folder. It refuses to overwrite a file at the target path that it did not install. A per-user install warns when `~/.local/bin` is not on `PATH` and prints the line to add to `~/.bashrc` or `~/.zshrc`.

## Upgrade

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The uninstall section provides docker volume rm mql-compiler-cache, which deletes cached toolchain data and can affect every user on the machine. While an inline comment mentions this impact, the section lacks a clear user-facing warning emphasizing that the operation is destructive and shared-system affecting.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

This is a direct external script fetch from GitHub followed by immediate execution, creating a classic remote-code-execution supply-chain risk. The danger is increased because the URL targets a mutable branch path, so script contents can change over time without the user noticing.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

If mql-compiler is not on PATH, install it for the current user:

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mql-compiler/master/install.sh | bash

It lands in ~/.local/bin; if that is not on PATH, the installer prints the line to add. For system-wide installs, upgrades, uninstalling, custom installers and troubleshooting, see references/installation.md.

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

This command directly executes a script fetched from a remote URL without integrity verification or prior review. That creates an arbitrary code execution path under the user's account if the repository, hosting, or transport path is tampered with.

Content

Scanner excerpt · references/installation.md (reported line 10)May include surrounding context.

Per user, into ~/.local/bin:

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mql-compiler/master/install.sh | bash

System wide, into /usr/local/bin:

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

This is the same remote-script execution pattern, but elevated through sudo, so compromise of the fetched script results in immediate root-level arbitrary code execution. In skill context, this is especially dangerous because the documentation encourages privileged execution during installation.

Content

Scanner excerpt · references/installation.md (reported line 16)May include surrounding context.

System wide, into /usr/local/bin:

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mql-compiler/master/install.sh | sudo bash -s -- --system

| Option | Effect |

External Script Fetching

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The uninstall instructions again execute a remote script directly from a mutable GitHub URL. Even though the intent is removal, compromise of that script still enables arbitrary code execution on the host.

Content

Scanner excerpt · references/installation.md (reported line 43)May include surrounding context.

Uninstall

bash
curl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mql-compiler/master/install.sh | bash -s -- --uninstall
docker volume rm mql-compiler-cache   # also frees the toolchain, for every user on the machine

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

command -v mql-compiler # installed and on PATH mql-compiler --version # the image runs; shows its version and the MetaEditor builds (null before the first run) docker volume ls | grep mql-compiler-cache # toolchain cached (after the first run) docker run --rm -v mql-compiler-cache:/c busybox cat /c/uid-$(id -u)/logs/last-run.log # the last run's full output

text

## Troubleshooting

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/installation.md (reported line 55)May include surrounding context.

command -v mql-compiler # installed and on PATH mql-compiler --version # the image runs; shows its version and the MetaEditor builds (null before the first run) docker volume ls | grep mql-compiler-cache # toolchain cached (after the first run) docker run --rm -v mql-compiler-cache:/c busybox cat /c/uid-$(id -u)/logs/last-run.log # the last run's full output

text

## Troubleshooting

Static analysis

No suspicious patterns detected.