mt5-log-reader
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external MetaTrader 5 log files, creating a surface where untrusted data from log entries could influence agent behavior.
- Ingestion points: Runtime log files and compilation logs located within the MT5 directory structure, accessed via
ReadandGreptools. - Boundary markers: The skill lacks explicit delimiters for external content but provides instructions to the agent to filter sensitive information when reporting.
- Capability inventory: Access is limited to
Read,Grep, andBash. No network exfiltration or file-write tools are authorized in the frontmatter. - Sanitization: The instructions explicitly advise the agent to filter sensitive trading data (symbol names, account info) before providing output to the user.
- [COMMAND_EXECUTION]: The skill utilizes bash snippets to dynamically determine log file paths based on the system date.
- Evidence: The workflow uses
date +"%Y%m%d"to construct theLOG_FILEpath. - Context: The command execution is restricted to environment variable expansion and date formatting, which is a standard procedure for log rotation analysis and does not involve direct user-input interpolation.
Audit Metadata