Caveat verdict

mt5-httpapi

88
๐ŸŸข Trusted
No high-risk patterns surfaced by the deep scan โ€” automated capability review, not behavioral proof.

MetaTrader 5 HTTP bridge client with strong safety guardrails requiring explicit per-action user confirmation before any mutating trade calls and prohibiting autonomous credential harvesting from config files.

โš  Flagged for review โ€” coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.

Automated static analysis โ€” not a human review. Caveat flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.

5
security
70
transparency
70
maintenance

Permission integrity

Makes network requests but does not declare curl/wget in required binaries

network_out

Findings (4)

Pattern match critical

Possible hardcoded credential

references/setup.md ยท code ยท token: "your-token-here

Pattern match high

HTTP request to bare IP address โ€” common in malicious payloads

references/setup.md ยท code ยท http://20.20.20.1

Pattern match high

References sudo โ€” requests elevated privileges

references/setup.md ยท code ยท sudo

Pattern match medium

Instructs covert action โ€” may act without user awareness

SKILL.md ยท prose ยท downgraded ยท silently

Permissions & capabilities

No declared permissions โ€” minimal attack surface.

network_out

Is this flag fair?

Check another skill Browse the registry Auditing your own skills or configs? Use the API