tradingview-mcp-assistant

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires cloning a repository from an unverified source (github.com/tradesdontlie/tradingview-mcp.git) to provide the MCP server functionality.
  • [REMOTE_CODE_EXECUTION]: The installation process involves executing shell and batch scripts (e.g., launch_tv_debug_mac.sh, launch_tv_debug.bat) from the external repository to configure the local environment.
  • [COMMAND_EXECUTION]: Setup instructions include manual command execution for global package linking and enabling debug ports on the local TradingView application.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from TradingView indicator values, drawings, and Pine Script console logs without boundary markers, while possessing the capability to inject and compile Pine Script code and capture screenshots to the local filesystem.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 10:44 PM
Security Audit — agent-trust-hub — tradingview-mcp-assistant