alpaca-trading-paper-trading

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is focused on paper trading and incorporates rigorous safety checks to prevent live trading, such as mandatory verification of the API base URL for the 'paper-' prefix before every submission.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill follows security best practices by instructing the agent to read API keys from environment variables or configuration files and explicitly prohibiting the disclosure of secrets in chat.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (backtest results, alerts, and manual trade ideas), it mitigates injection risks through mandatory visual order previews and an explicit confirmation workflow (Confirmation-ON mode) before any network action is taken.
  • [EXTERNAL_DOWNLOADS]: All suggested dependencies and libraries are official SDKs from the vendor or standard, well-known networking packages. All documentation links point to the official Alpaca Markets domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 09:25 PM
Security Audit — agent-trust-hub — alpaca-trading-paper-trading