alpaca-trading
Fail
Audited by Socket on Mar 18, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
Purpose and capabilities are aligned: this is genuinely a trading skill. It is not overtly malicious, but it is high risk because it empowers an AI agent to perform live financial actions and forwards brokerage credentials to a third-party CLI installed via external tooling.
Confidence: 89%Severity: 81%
Audit Metadata