alpaca-trading-mcp
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is purpose-aligned and mainly uses official sources, so it does not look malicious. However, it is still high-impact because it installs external tooling, forwards brokerage credentials to a package/runtime, and enables autonomous financial actions including live trading; classify as BENIGN in intent but MEDIUM/HIGH security risk.
Confidence: 89%Severity: 62%
Audit Metadata