Back to skill

Security audit

mt5-httpapi

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed MT5 trading bridge client with real-money risk, but its high-impact actions are purpose-aligned and gated by explicit user confirmation instructions.

Install only if you intentionally run mt5-httpapi and understand it can place, change, or close real brokerage trades. Use a demo account first, set a strong API token, keep MT5_API_URL on localhost or behind strong access controls, and require exact confirmation before any order, position, deployment, terminal-control, or sensitive file change.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (13)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The skill exposes position-closing operations that directly realize gains or losses on a live account, with no undo. If an attacker or confused agent supplies the wrong position id, symbol, or volume, it can close the wrong trade and cause immediate financial harm.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
This API moves real money on a real brokerage account. Mutating endpoints are irreversible, so precision beats enthusiasm every fucking time.

**Real-money mutations.** `POST /orders`, `PUT /orders/<id>`, `DELETE /orders/<id>`, `PUT /positions/<id>`, and `DELETE /positions/<id>` open, modify, cancel, or close a real order/position on a live MetaTrader 5 account with no undo — a filled market order or a closed position can only be offset by a separate trade at a new price. Call one only for the exact action the user requested, after confirming ticket, symbol, side, volume, price, SL, TP, and account. Never enumerate and then bulk-close/cancel on inferred intent. `order_send` is a single call with no client-side auto-retry; after an error or timeout, report it and get fresh confirmation before resubmitting.

**Live EA deployments.** `POST /deployments`, `PATCH /deployments/<id>`, `DELETE /deployments/<id>` and `POST /charts/<id>/close` start, re-point, pause or stop an Expert Advisor running on a chart of a real account, and that EA trades on its own. Confirm the expert, set file, symbol, timeframe and account before each one, exactly like a trade. `PUT /webrequest` and `POST /webrequest/apply` restart the terminal when it runs on bare metal rather than in the Windows VM.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The skill exposes position-closing operations that directly realize gains or losses on a live account, with no undo. If an attacker or confused agent supplies the wrong position id, symbol, or volume, it can close the wrong trade and cause immediate financial harm.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
This API moves real money on a real brokerage account. Mutating endpoints are irreversible, so precision beats enthusiasm every fucking time.

**Real-money mutations.** `POST /orders`, `PUT /orders/<id>`, `DELETE /orders/<id>`, `PUT /positions/<id>`, and `DELETE /positions/<id>` open, modify, cancel, or close a real order/position on a live MetaTrader 5 account with no undo — a filled market order or a closed position can only be offset by a separate trade at a new price. Call one only for the exact action the user requested, after confirming ticket, symbol, side, volume, price, SL, TP, and account. Never enumerate and then bulk-close/cancel on inferred intent. `order_send` is a single call with no client-side auto-retry; after an error or timeout, report it and get fresh confirmation before resubmitting.

**Live EA deployments.** `POST /deployments`, `PATCH /deployments/<id>`, `DELETE /deployments/<id>` and `POST /charts/<id>/close` start, re-point, pause or stop an Expert Advisor running on a chart of a real account, and that EA trades on its own. Confirm the expert, set file, symbol, timeframe and account before each one, exactly like a trade. `PUT /webrequest` and `POST /webrequest/apply` restart the terminal when it runs on bare metal rather than in the Windows VM.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Deployment deletion and related terminal-control operations can stop or alter live Expert Advisors that trade autonomously on a real account. Because one wrong broker/account selection or deployment id can disable automated trading or restart the wrong terminal, the parameter abuse risk is substantial.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
**Real-money mutations.** `POST /orders`, `PUT /orders/<id>`, `DELETE /orders/<id>`, `PUT /positions/<id>`, and `DELETE /positions/<id>` open, modify, cancel, or close a real order/position on a live MetaTrader 5 account with no undo — a filled market order or a closed position can only be offset by a separate trade at a new price. Call one only for the exact action the user requested, after confirming ticket, symbol, side, volume, price, SL, TP, and account. Never enumerate and then bulk-close/cancel on inferred intent. `order_send` is a single call with no client-side auto-retry; after an error or timeout, report it and get fresh confirmation before resubmitting.

**Live EA deployments.** `POST /deployments`, `PATCH /deployments/<id>`, `DELETE /deployments/<id>` and `POST /charts/<id>/close` start, re-point, pause or stop an Expert Advisor running on a chart of a real account, and that EA trades on its own. Confirm the expert, set file, symbol, timeframe and account before each one, exactly like a trade. `PUT /webrequest` and `POST /webrequest/apply` restart the terminal when it runs on bare metal rather than in the Windows VM.

**Terminal control.** `POST /terminal/shutdown` disconnects this API process from the MT5 SDK but leaves `terminal64.exe` running. `POST /terminal/restart` kills and relaunches only the selected terminal process and can make that terminal unavailable for several minutes. Confirm the selected broker/account/instance and exact operation before either call.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This section documents order creation, modification, and cancellation on a live brokerage account, which are highly sensitive parameterized actions. The danger is amplified by the financial context: a malformed symbol, side, volume, price, or account route can immediately place or alter real-money orders.

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

Orders

Mutating endpoints — confirmation required. Every POST /orders, PUT /orders/<id>, and DELETE /orders/<id> opens, modifies, or cancels a real order on the user's brokerage account. Before invoking any of them you MUST: (1) print the full resolved request (account login from GET /account, broker URL prefix, symbol, side, volume, price, SL, TP); (2) ask the user to confirm that specific action; (3) wait for an explicit yes. A prior confirmation does not carry over to a new action.

bash
# Place market order — only after explicit per-action confirmation from the user.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This section enables modification and closure of live positions, which are financially destructive if parameters are wrong or manipulated. Partial close support increases the chance of subtle abuse, since changing only volume can still materially alter exposure and realized P&L.

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

Positions

Mutating endpoints — confirmation required. PUT /positions/<id> changes the SL/TP of a live position, and DELETE /positions/<id> closes it (full or partial). Both move real money. Per-action confirmation rule above applies — print symbol, ticket, current price, the change being made, and wait for explicit user yes.

bash
curl -H "Authorization: Bearer $MT5_API_TOKEN" $MT5_API_URL/positions

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

The file API includes delete operations on terminal-side paths, creating a parameter abuse surface where the wrong path could remove trading components, logs, or supporting code. In this context, file deletion can indirectly change trading behavior or disable parts of the MT5 environment, making the impact more severe than ordinary file management.

Content

Scanner excerpt · SKILL.md (reported line 405)May include surrounding context.

md
### Files

**Off by default.** The operator turns it on with `files.enabled: true` in `config.yaml`; a terminal can opt out with `files: false`. Without it these routes answer `404`. `GET /files/<path>` lists a directory or downloads a file in the terminal's install directory (the folder with `terminal64.exe`), `PUT /files/<path>` uploads one (raw body or a multipart `file` field), `PUT /files/<dir>?extract` unpacks a zip into that directory, and `DELETE /files/<path>` (`?recursive` for a non-empty directory) removes it. `/compile/files/...` does the same on the MQL5 tree `POST /compile` builds against, which is where a shared `.mqh` library goes. The MCP tools are `list_files`, `get_file`, `put_file` and `delete_file`, with `tree` set to `terminal` or `compile`.

The broker credentials (`mt5start.ini`, `Config/accounts.dat`) are never served, and the terminal's executables and Chart Deployments' own files are read-only here. **Writing into `MQL5/Experts`, `MQL5/Libraries` or `MQL5/Include` changes what experts on that account run, and a DLL in `MQL5/Libraries` runs inside the terminal: do it only when the user asked for that exact change, and confirm the terminal first.** Reading files and logs needs no confirmation.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The skill is explicitly designed to send account data and trading instructions over HTTP to a user-provided MT5 bridge, which is an external transmission of sensitive financial information and control data. Although this is the intended purpose of the skill and it includes cautions about self-hosted endpoints and optional auth, compromise or misconfiguration of MT5_API_URL could expose brokerage data or enable unauthorized trading actions.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: mt5-httpapi
description: HTTP client for a user-deployed mt5-httpapi MetaTrader 5 bridge. Use ONLY when the user has explicitly installed and configured mt5-httpapi AND provided MT5_API_URL. Read endpoints (account, symbols, rates, ticks, server-side technical-analysis enrichment via the wickworks sidecar, history, backtest report fetching) are safe to invoke. Trade-mutating endpoints on /orders and /positions require explicit per-action confirmation showing symbol, side, volume, and SL/TP; terminal shutdown/restart also require explicit confirmation naming the target terminal and operation. Creating, changing or deleting a chart deployment (/deployments) or closing a chart starts or stops a live EA and needs the same confirmation. Never invoke mutations on inferred intent. Do not use this skill for generic market-data, charting, or trading questions where the user hasn't named mt5-httpapi.
compatibility: Requires curl and a user-deployed mt5-httpapi instance. MT5_API_URL env var must be set by the user. MT5_API_TOKEN is required whenever the server has auth configured; the agent must obtain it from MT5_API_TOKEN env var OR by asking the user — never by reading repository config files autonomously.
metadata:
  author: psyb0t
  homepage: https://github.com/psyb0t/mt5-httpapi

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
`from` and `to` accept three formats (all real UTC): unix seconds (`1700000000`), full datetime `YYYY_MM_DD_HH_MM_SS` (`2024_01_15_14_30_00`), or date-only `YYYY_MM_DD` (midnight UTC).

Capped at `terminal_info().maxbars` rows per request (default 100k — see `GET /terminal`). Symbols auto-select into MarketWatch on first access. Responses are gzipped if the client requests it (`curl --compressed`).

Tick `flags` param: `ALL` (default), `INFO` (bid/ask only — ~10× smaller), `TRADE` (trades only).

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This endpoint uploads local expert advisor and set files to the remote MT5 service, transmitting potentially sensitive trading logic or proprietary artifacts outside the local environment. In context, these uploads can directly affect what code runs on a live trading terminal, so sending the wrong file or sending to the wrong account/host has significant operational and financial risk.

Content

Scanner excerpt · SKILL.md (reported line 357)May include surrounding context.

md
# "navigator_refresh" must be "ok" before a deployment of a NEW expert can
# attach: on "failed" upload the same file again, on "unavailable" (bare metal)
# the terminal needs a restart first.
curl -H "Authorization: Bearer $MT5_API_TOKEN" \
  -F "expert=@HappyGoldScalp.ex5" "$MT5_API_URL/experts"
curl -H "Authorization: Bearer $MT5_API_TOKEN" \
  -F "set=@gold-m5.set" "$MT5_API_URL/sets"   # returns the parsed inputs

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The file API permits writes and deletes in terminal and compile trees, including locations that change what code an EA runs, yet the confirmation guidance is narrower than the actual risk surface. An agent using these capabilities could modify trading logic, add DLL-backed components, or remove critical files with only partial safeguards, leading to arbitrary code execution in the terminal or unsafe trading behavior.

Content

Scanner excerpt · SKILL.md (reported line 407)May include surrounding context.

Off by default. The operator turns it on with files.enabled: true in config.yaml; a terminal can opt out with files: false. Without it these routes answer 404. GET /files/<path> lists a directory or downloads a file in the terminal's install directory (the folder with terminal64.exe), PUT /files/<path> uploads one (raw body or a multipart file field), PUT /files/<dir>?extract unpacks a zip into that directory, and DELETE /files/<path> (?recursive for a non-empty directory) removes it. /compile/files/... does the same on the MQL5 tree POST /compile builds against, which is where a shared .mqh library goes. The MCP tools are list_files, get_file, put_file and delete_file, with tree set to terminal or compile.

The broker credentials (mt5start.ini, Config/accounts.dat) are never served, and the terminal's executables and Chart Deployments' own files are read-only here. Writing into MQL5/Experts, MQL5/Libraries or MQL5/Include changes what experts on that account run, and a DLL in MQL5/Libraries runs inside the terminal: do it only when the user asked for that exact change, and confirm the terminal first. Reading files and logs needs no confirmation.

bash
# Unpack a library into the compile tree, then compile against it

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 485)May include surrounding context.

file.

bash
curl -sS -X POST -H "Authorization: Bearer $MT5_API_TOKEN" \
  -H "Content-Type: application/json" \
  $MT5_API_URL/backtest/build-set \
  -d '{

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/setup.md (reported line 166)May include surrounding context.

bash
# Install cloudflared
curl -L https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64 -o /tmp/cloudflared
sudo install /tmp/cloudflared /usr/local/bin/cloudflared

# Authenticate and create tunnel
cloudflared tunnel login

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup.md (reported line 168)May include surrounding context.

md
curl -L https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64 -o /tmp/cloudflared
sudo install /tmp/cloudflared /usr/local/bin/cloudflared

# Authenticate and create tunnel
cloudflared tunnel login
cloudflared tunnel create mt5-httpapi

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:57