ClawAudit verdict
tradememory
MT5 trading memory system that stores trade data locally on localhost:8000 with explicit disclosure that it makes no outbound network requests at runtime; MT5 credentials are optional and used only for local sync, with install network access limited to PyPI and GitHub.
โ Flagged for review โ coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis โ not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
package_install
Findings (2)
Possible hardcoded credential
SKILL.md ยท frontmatter ยท PASSWORD: "MetaTrader 5 password (optional, MT5 sync only)
Python os.getenv โ reads environment variable
scripts/setup_mt5.sh ยท prose ยท downgraded ยท os.getenv(
Permissions & capabilities
Requires 2 system binaries. (1 elevated: pip).
package_installnetwork_in Is this flag fair?
Thanks โ recorded.