alpaca-trade-api-sdk
Pass
Audited by Gen Agent Trust Hub on Jul 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides architectural guidance and mental models for using the Alpaca Trade API SDK.
- [CREDENTIALS_UNSAFE]: The skill provides instructions on secure credential management, recommending the use of environment variables (APCA_API_KEY_ID, APCA_API_SECRET_KEY, APCA_API_OAUTH_TOKEN) and explicitly advising against passing API keys as plain strings in code.
- [EXTERNAL_DOWNLOADS]: The skill references the official @alpacahq/alpaca-trade-api package, which is a legitimate vendor resource consistent with the skill's authorship.
Audit Metadata