alpaca-trading

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherently scoped to its stated purpose of facilitating Alpaca trading via the apcacli CLI. It uses official installation sources (crates.io) and credential handling via environment variables, which is proportionate for a developer tooling skill. Data flows to Alpaca APIs for trading and data retrieval are appropriate for the described functionality and do not reveal unexpected exfiltration patterns. The primary security considerations are standard credential handling (env vars) and the financial risk inherent to trading tools; no explicit credential harvesting, malware, or covert data leakage patterns are evident. Overall, the footprint is Benign with elevated risk due to the trading domain, but not suspicious in its current form.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 11:17 PM
Package URL
pkg:socket/skills-sh/lacymorrow%2Falpaca-trading-skill%2Falpaca-trading%2F@ec07d12913f0cad67c535469b0c67a2793acd622