tradingview-mcp

Warn

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill downloads and executes an external Python-based MCP server from an untrusted third-party repository (github.com/atilaahmettaner/tradingview-mcp) using the uvx tool at runtime. Although the server is pinned to a specific Git SHA, this involves executing remote code from a non-trusted maintainer.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external market news and sentiment APIs, which constitutes an attack surface for indirect prompt injection.
  • Ingestion points: Data returned by market_sentiment, financial_news, and other combined analysis tools listed in SKILL.md.
  • Boundary markers: The instructions lack explicit delimiters or 'ignore' instructions for the agent when processing news or sentiment summaries.
  • Capability inventory: The skill provides a comprehensive suite of 37 read-only financial tools but does not have file-write or system-altering capabilities.
  • Sanitization: No sanitization, escaping, or validation of the external content is described or implemented in the instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 26, 2026, 12:30 PM
Security Audit — agent-trust-hub — tradingview-mcp