alpaca
Pass
Audited by Gen Agent Trust Hub on Apr 30, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing the
@membranehq/clipackage via npm. This is the official tool required for interacting with the Membrane platform described in the documentation. - [COMMAND_EXECUTION]: The skill provides instructions for using several
membraneCLI commands to manage authentication (login), establish connections (connect), and execute trading actions (action run). All commands are within the scope of the skill's stated purpose of managing Alpaca data. - [CREDENTIALS_UNSAFE]: The instructions explicitly follow security best practices by advising the agent to never request API keys from the user, instead utilizing a managed connection service to handle the authentication lifecycle.
Audit Metadata