tradingview-mcp
Warn
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill downloads and executes an external Python-based MCP server from an untrusted third-party repository (
github.com/atilaahmettaner/tradingview-mcp) using theuvxtool at runtime. Although the server is pinned to a specific Git SHA, this involves executing remote code from a non-trusted maintainer. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external market news and sentiment APIs, which constitutes an attack surface for indirect prompt injection.
- Ingestion points: Data returned by
market_sentiment,financial_news, and other combined analysis tools listed inSKILL.md. - Boundary markers: The instructions lack explicit delimiters or 'ignore' instructions for the agent when processing news or sentiment summaries.
- Capability inventory: The skill provides a comprehensive suite of 37 read-only financial tools but does not have file-write or system-altering capabilities.
- Sanitization: No sanitization, escaping, or validation of the external content is described or implemented in the instructions.
Audit Metadata