Tradestaq Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Tradestaq Mcp (Agent Skill) and scored it 91/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} is the classic direct prompt-injection phrasing. Placed in a skill body that the agent reads as trusted instructions, it tries to make the agent abandon its prior rules and follow whatever comes next — a full system-prompt override.
ignore/disregard/forget … previous instructions sentence.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
31 AI-powered trading tools for Claude, Cursor, and any MCP client.
Create strategies, backtest them, deploy trading bots, copy top traders, monitor positions, and manage your crypto portfolio, all from conversation. Supports Binance, Bybit, OKX, Bitget, Hyperliquid, dYdX, and more.
"Show me my portfolio" → get_portfolio
"Backtest GhostRider on BTC/USDT for 3 months" → what_if_backtest
"Deploy it on my Binance account" → deploy_bot
"Who are the top traders this month?" → list_top_traders
"Generate a momentum strategy for ETH" → generate_strategyFor MCP clients that support HTTP transport:
{
"mcpServers": {
"tradestaq": {
"url": "https://mcp.tradestaq.com/mcp"
}
}
}No clone, no build. Just add to your MCP config:
Claude Desktop (~/Library/Application Support/Claude/claude_desktop_config.json):
{
"mcpServers": {
"tradestaq": {
"command": "npx",
"args": ["-y", "@the-staq/tradestaq-mcp"]
}
}
}Cursor (.cursor/mcp.json):
{
"mcpServers": {
"tradestaq": {
"command": "npx",
"args": ["-y", "@the-staq/tradestaq-mcp"]
}
}
}Claude Code:
claude mcp add tradestaq -- npx -y @the-staq/tradestaq-mcpgit clone https://github.com/the-staq/tradestaq-mcp.git
cd tradestaq-mcp
npm install
npm run buildThen point your MCP client to dist/index.js.
After adding the server, ask your AI assistant to log in:
Credentials never enter the chat when using the browser flow. Token is stored locally at ~/.tradestaq/mcp-config.json with restricted permissions (0600).
| Tool | Description |
|---|---|
login | Log in with email and password |
authenticate | Log in via browser (OAuth + PKCE) |
check_auth | Check authentication status |
set_token | Manually set a JWT token |
connect_exchange | Connect an exchange account via browser |
logout | Remove stored credentials |
| Tool | Description |
|---|---|
get_price | Current price, 24h change, volume |
get_candles | OHLCV candlestick data (1m to 1d) |
list_exchanges | List connected exchange accounts |
search_markets | Find trading pairs on a specific exchange |
| Tool | Description |
|---|---|
get_portfolio | Total balance, exchanges, active bots |
get_positions | Open positions with live PnL |
| Tool | Description |
|---|---|
list_strategies | Browse marketplace or your own strategies |
get_strategy | Full strategy details and performance |
explain_strategy | Plain-English explanation with risk profile |
compare_strategies | Side-by-side metrics comparison |
create_strategy | Create a strategy from TradeDroid code |
generate_strategy | Generate a strategy from natural language using AI |
| Tool | Description |
|---|---|
what_if_backtest | Run a historical backtest (async, 30-120s) |
get_backtest_results | Check status of a running backtest |
| Tool | Description |
|---|---|
list_bots | All bots with status and performance |
get_bot_status | Detailed bot metrics and config |
deploy_bot | Deploy a strategy as a trading bot |
stop_bot | Stop a running bot |
close_position | Close an open position (full or partial) |
deploy_bot defaults to paper trading. Pass live: true for real money.
| Tool | Description |
|---|---|
get_trade_history | Closed trades with PnL, entry/exit prices |
get_performance_metrics | ROI, win rate, Sortino ratio, PnL breakdown |
| Tool | Description |
|---|---|
list_top_traders | Browse the leaderboard of top traders |
follow_trader | Subscribe to copy a trader's trades |
| Tool | Description |
|---|---|
suggest_strategies | Match strategies to your risk profile |
get_market_context | Trend, volatility, support/resistance for a symbol |
Trading Assistant — Start a conversation about your portfolio and positions. The AI calls get_portfolio and get_positions to ground its responses in your actual data.
Strategy Builder — Walk through creating, backtesting, and deploying a strategy. Pass an optional goal like "momentum strategy for ETH" to get focused suggestions.
Portfolio Reviewer — Deep analysis of your portfolio, positions, trade history, and performance. Identifies what's working, what isn't, and suggests improvements.
MCP resources provide browsable data that AI clients can read directly:
| Resource | URI | Description |
|---|---|---|
| Portfolio | tradestaq://portfolio | Balances, positions, and active bots |
| Bots | tradestaq://bots | All bots with status and PnL |
| Strategies | tradestaq://strategies | Strategy catalog with ratings |
stdio HTTPS
┌──────────────┐◄──────────►┐ ┌────────────────►┌──────────────┐
│Claude Desktop│ │ │ │ │
│Cursor / CLI │ │ tradestaq-mcp │ Bearer JWT │ TradeStaq │
└──────────────┘ │ 31 tools │◄────────────────│ API │
│ 3 prompts │ │ │
┌──────────────┐ HTTP+SSE │ 3 resources │ └──────────────┘
│ Any MCP │◄──────────►│ │
│ client (web) │ └──────────────────┘
└──────────────┘--http flag)https://mcp.tradestaq.com/mcp for remote clientsnpm run dev # watch mode with tsx
npm run build # compile TypeScript
npm run lint # type check without emitting
npm test # run tests
npm start # run server (stdio)
npm run start:http # run server (HTTP+SSE on port 3100)All tool errors return structured responses:
{
"error": {
"code": "INSUFFICIENT_BALANCE",
"message": "Human-readable description",
"retryable": true,
"retryAfterMs": 5000
}
}Error codes: AUTH_EXPIRED, TIMEOUT, RATE_LIMITED, NETWORK_ERROR, HTTP_4xx, HTTP_5xx.
deploy_bot, stop_bot, close_position, and follow_trader are destructive operations (AI confirms with user)MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.