alpaca-trading-mcp

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is purpose-aligned and mainly uses official sources, so it does not look malicious. However, it is still high-impact because it installs external tooling, forwards brokerage credentials to a package/runtime, and enables autonomous financial actions including live trading; classify as BENIGN in intent but MEDIUM/HIGH security risk.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
May 17, 2026, 10:52 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fmcp-skills%2Falpaca-trading-mcp%2F@4168dc9d98a08bade04c899e7f9d41ee88f8172c
Security Audit — socket — alpaca-trading-mcp