alpaca-ts-alpha-sdk

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and usage idioms for the @alpacahq/alpaca-ts-alpha package. These are recognized vendor resources associated with the author 'alpacahq'.
  • [SAFE]: Secret management instructions correctly advise the use of environment variables (e.g., APCA_API_KEY_ID, APCA_API_SECRET_KEY) for authentication, which is a standard security best practice. No hardcoded credentials or sensitive file access patterns were found.
  • [SAFE]: The skill does not contain any obfuscated code, remote script execution (e.g., curl|bash), or unauthorized network operations. All discussed functionalities (REST API calls and WebSockets) are standard for the intended trading and market data use cases.
  • [SAFE]: No privilege escalation, persistence mechanisms, or prompt injection attempts were identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 09:20 AM
Security Audit — agent-trust-hub — alpaca-ts-alpha-sdk