alpaca-trading

Warn

Audited by Snyk on Mar 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly designed for trading via Alpaca's API (apcacli). It contains concrete commands to submit, modify, and cancel market/limit/stop/trailing orders (e.g., "apcacli order submit buy AAPL --quantity 10", "order cancel", "position close", "order cancel-all"), manages live vs paper trading via API keys and base URL, and supports trading stocks, ETFs, options, and crypto. This is a specific tool whose primary purpose is to execute financial transactions (market orders), so it grants direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 3, 2026, 08:31 PM