alpaca-trading-hardened

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is coherent and not obviously malicious, but it gives an AI agent high-impact financial trading capability and routes sensitive trading credentials through a third-party CLI. The main issue is autonomous real-world action risk, with moderate supply-chain risk from relying on non-official Alpaca tooling.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Apr 21, 2026, 06:32 PM
Package URL
pkg:socket/skills-sh/faberlens%2Fhardened-skills%2Falpaca-trading-hardened%2F@c53843e6353a654ac4ef348700c18c59ba636910
Security Audit — socket — alpaca-trading-hardened