alpaca-trade-api-sdk

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides architectural guidance and mental models for using the Alpaca Trade API SDK.
  • [CREDENTIALS_UNSAFE]: The skill provides instructions on secure credential management, recommending the use of environment variables (APCA_API_KEY_ID, APCA_API_SECRET_KEY, APCA_API_OAUTH_TOKEN) and explicitly advising against passing API keys as plain strings in code.
  • [EXTERNAL_DOWNLOADS]: The skill references the official @alpacahq/alpaca-trade-api package, which is a legitimate vendor resource consistent with the skill's authorship.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 04:39 PM
Security Audit — agent-trust-hub — alpaca-trade-api-sdk