miniqmt

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external financial markets and company reports which could potentially be manipulated to include adversarial instructions intended to influence the agent's trading decisions.
  • Ingestion points: scripts/market_data.py, scripts/financial_data.py, and scripts/sector_data.py fetch data from the xtquant library which connects to the local MiniQMT client.
  • Boundary markers: The skill does not implement explicit boundary markers or instructions for the agent to ignore embedded commands in the fetched data.
  • Capability inventory: scripts/trade.py provides the ability to place orders, cancel orders, and query account assets.
  • Sanitization: The scripts return raw data in JSON format without specific sanitization for prompt injection patterns.
  • [EXTERNAL_DOWNLOADS]: The documentation provides links to download the xtquant library and historical datasets from the official vendor's domain (dict.thinktrader.net). These are legitimate and expected resources for the quantitative trading platform.
  • [COMMAND_EXECUTION]: The skill facilitates the execution of Python scripts (scripts/market_data.py, scripts/trade.py, etc.) that interact with the local MiniQMT quantitative trading terminal via the xtquant library.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 03:36 PM
Security Audit — agent-trust-hub — miniqmt