miniqmt
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external financial markets and company reports which could potentially be manipulated to include adversarial instructions intended to influence the agent's trading decisions.
- Ingestion points:
scripts/market_data.py,scripts/financial_data.py, andscripts/sector_data.pyfetch data from thextquantlibrary which connects to the local MiniQMT client. - Boundary markers: The skill does not implement explicit boundary markers or instructions for the agent to ignore embedded commands in the fetched data.
- Capability inventory:
scripts/trade.pyprovides the ability to place orders, cancel orders, and query account assets. - Sanitization: The scripts return raw data in JSON format without specific sanitization for prompt injection patterns.
- [EXTERNAL_DOWNLOADS]: The documentation provides links to download the
xtquantlibrary and historical datasets from the official vendor's domain (dict.thinktrader.net). These are legitimate and expected resources for the quantitative trading platform. - [COMMAND_EXECUTION]: The skill facilitates the execution of Python scripts (
scripts/market_data.py,scripts/trade.py, etc.) that interact with the local MiniQMT quantitative trading terminal via thextquantlibrary.
Audit Metadata