alpaca-ts-alpha-sdk
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and usage idioms for the
@alpacahq/alpaca-ts-alphapackage. These are recognized vendor resources associated with the author 'alpacahq'. - [SAFE]: Secret management instructions correctly advise the use of environment variables (e.g.,
APCA_API_KEY_ID,APCA_API_SECRET_KEY) for authentication, which is a standard security best practice. No hardcoded credentials or sensitive file access patterns were found. - [SAFE]: The skill does not contain any obfuscated code, remote script execution (e.g., curl|bash), or unauthorized network operations. All discussed functionalities (REST API calls and WebSockets) are standard for the intended trading and market data use cases.
- [SAFE]: No privilege escalation, persistence mechanisms, or prompt injection attempts were identified.
Audit Metadata