alpaca-broker-journals

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional content for interacting with the Alpaca Broker API. All referenced domains (alpaca.markets) belong to the official vendor infrastructure. No executable scripts, obfuscated code, or unauthorized data exfiltration patterns were found.
  • [PROMPT_INJECTION]: The skill identifies the description field in the Alpaca Journal API as a user-controllable string (up to 1024 characters). While this represents a potential surface for indirect prompt injection if an agent processes this data in a downstream task, the skill itself does not provide exploitable capabilities or autonomous execution logic based on this field.
  • [DATA_EXPOSURE]: The skill mentions the use of HTTP Basic Authentication and account UUIDs, which are standard requirements for the Alpaca Broker API. It correctly advises the use of idempotency keys for transaction safety and provides no evidence of hardcoded credentials or sensitive data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 02:38 AM
Security Audit — agent-trust-hub — alpaca-broker-journals