alpaca-broker-journals
Pass
Audited by Gen Agent Trust Hub on Jun 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides instructional content for interacting with the Alpaca Broker API. All referenced domains (alpaca.markets) belong to the official vendor infrastructure. No executable scripts, obfuscated code, or unauthorized data exfiltration patterns were found.
- [PROMPT_INJECTION]: The skill identifies the
descriptionfield in the Alpaca Journal API as a user-controllable string (up to 1024 characters). While this represents a potential surface for indirect prompt injection if an agent processes this data in a downstream task, the skill itself does not provide exploitable capabilities or autonomous execution logic based on this field. - [DATA_EXPOSURE]: The skill mentions the use of HTTP Basic Authentication and account UUIDs, which are standard requirements for the Alpaca Broker API. It correctly advises the use of idempotency keys for transaction safety and provides no evidence of hardcoded credentials or sensitive data exposure.
Audit Metadata