ibkr-api-skill
Warn
Audited by Snyk on Mar 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill is explicitly designed for brokerage operations and includes concrete, specific APIs and functions to execute trades and manage accounts. It documents TWS/Client Portal endpoints (e.g., placeOrder(account_id, contract, order); POST /iserver/account/{id}/orders), MCP server tools that include place_order and order-cancellation, multi-account order routing, IRA write-operation restrictions, and trade-execution patterns. These are direct market-order/brokerage execution capabilities (not generic tooling), therefore it grants Direct Financial Execution Authority.
Issues (1)
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata