ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      canvascn00-crypto

      Safety Report

      Mt5 Trading Assistant Pro

      @canvascn00-crypto

      Professional-grade MetaTrader 5 trading automation — 35+ indicators, AI-powered strategy generation, smart risk management, and autonomous market scanning. C...

      164Downloads
      0Installs
      1Stars
      5Versions
      Workflow Automation8,822Security & Compliance3,689

      Security Analysis

      medium confidence
      Suspicious0.12 risk

      The skill's instructions mostly match an MT5 assistant, but a few unexplained or unverifiable claims (local-only storage, 'self_updating', and autonomous trade execution) and ambiguous runtime assumptions make the package internally inconsistent and worth caution.

      Apr 4, 20263 files5 concerns
      Purpose & Capabilityconcern

      The name/description claim an MT5 trading assistant and the SKILL.md requests only MT5 connection info (account number, access code, broker gateway), which is appropriate for MT5 automation. However, version.json lists features like "self_updating" and "trade_automation" while there is no install spec, no update mechanism, and no code to perform updates or verify authenticity. The promise that credentials are "saved locally only" is also unverifiable in this instruction-only skill. These mismatches (feature claims vs absent install/update code and unverifiable storage guarantees) are inconsistent with the declared package contents.

      Instruction Scopeconcern

      SKILL.md instructs collecting sensitive connection credentials and tells the agent to use the local MetaTrader5 Python library, and even suggests running `pip install MetaTrader5` if missing. It also offers an "Execute strategy" action and autonomous scanning/automation features but provides no explicit safe-confirmation steps before executing trades, no audit/logging or confirmation prompts, and no guidance on how/where credentials are stored. The document asserts that data is never transmitted externally, but an instruction-only skill cannot enforce or prove that; the behavior depends on the agent runtime (which may be remote). These gaps create scope creep risk: the instructions permit actions (installing packages, connecting to a terminal, executing trades) that have significant side effects yet lack safety controls or provenance.

      Install Mechanismnote

      There is no formal install spec and no code files to run; that's lower risk. However, SKILL.md instructs the agent/user to run `pip install MetaTrader5` if the Python library is absent — that instruction could cause the environment to download third-party packages at runtime. Because there's no declared source for self-updates or package pinning, that step introduces moderate risk (unverified third-party package fetch) even though the skill itself doesn't include an installer.

      Credentialsnote

      The skill does not request any environment variables or system config paths, which is appropriate. It does ask the user to provide account number, access (trading) code, and broker gateway — these are the minimal sensitive items needed to connect to MT5 and are proportionate to the described functionality. That said, the SKILL.md's promise that those credentials are saved locally and "never transmitted" is a behavioral claim that cannot be validated from the files provided. The presence of features like "self_updating" raises the possibility of network activity that could contradict the local-only claim.

      Persistence & Privilegenote

      The skill does not request always: true and is user-invocable only, which is appropriate. However, the skill advertises autonomous market scanning and trade automation, and the platform default allows the agent to invoke skills autonomously (disable-model-invocation: false). Combined with the ability to accept trading credentials and the lack of explicit confirmation/authorization rules in SKILL.md, this creates a meaningful operational risk: if the agent is allowed to act autonomously, it could place or modify live trades without additional safeguards. This is not proof of maliciousness, but users should treat it as a real capability requiring explicit controls.

      Guidance

      This package is instruction-only and looks like a legitimate MT5 assistant, but there are gaps you should clear before using it with real accounts. Ask the publisher these questions: (1) Where does the agent run — locally on your machine or in a cloud/hosted environment? The skill's "local-only" promise only holds if the agent runs locally. (2) How are credentials stored, encrypted, and deleted? Get exact storage path and encryption details. (3) Does the skill auto-update, and if so from what URL(s)? Request signed update mechanisms or a reproducible release source. (4) What safety guards exist before executing trades (explicit confirmations, dry-run/backtest-only defaults, rate limits, logging)? (5) If you must install packages (e.g., MetaTrader5 via pip), perform that in a controlled/sandboxed environment and prefer demo accounts for initial testing. If the author cannot provide source code, update endpoints, and clear confirmation workflows, treat this as risky for live trading and prefer not to enter live credentials until these questions are answered.

      Latest Release

      v4.0.1

      Reduced false-positive security flags. Replaced sensitive terms (password → code, login → account number). Cleaner language for safety scanner compatibility. Full functionality preserved. Default English, Chinese switchable.

      Popular Skills

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Summarize

      @summarize · 415 stars

      Published by @canvascn00-crypto on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]