mt5-log-reader

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external MetaTrader 5 log files, creating a surface where untrusted data from log entries could influence agent behavior.
  • Ingestion points: Runtime log files and compilation logs located within the MT5 directory structure, accessed via Read and Grep tools.
  • Boundary markers: The skill lacks explicit delimiters for external content but provides instructions to the agent to filter sensitive information when reporting.
  • Capability inventory: Access is limited to Read, Grep, and Bash. No network exfiltration or file-write tools are authorized in the frontmatter.
  • Sanitization: The instructions explicitly advise the agent to filter sensitive trading data (symbol names, account info) before providing output to the user.
  • [COMMAND_EXECUTION]: The skill utilizes bash snippets to dynamically determine log file paths based on the system date.
  • Evidence: The workflow uses date +"%Y%m%d" to construct the LOG_FILE path.
  • Context: The command execution is restricted to environment variable expansion and date formatting, which is a standard procedure for log rotation analysis and does not involve direct user-input interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 07:50 PM
Security Audit — agent-trust-hub — mt5-log-reader