alpaca-trading

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Purpose and capabilities are aligned: this is genuinely a trading skill. It is not overtly malicious, but it is high risk because it empowers an AI agent to perform live financial actions and forwards brokerage credentials to a third-party CLI installed via external tooling.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/lacymorrow%2Fopenclaw-alpaca-trading-skill%2Falpaca-trading%2F@9fd73de2cc0eb7332e1e21e73fb187d7f46cf571