alpaca

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent for an Alpaca integration, and its install source appears legitimate, but it materially increases trust by routing authentication and brokerage activity through Membrane rather than directly to Alpaca. The main security concern is high-impact autonomous financial actions plus third-party credential mediation, not confirmed malware.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Apr 30, 2026, 03:22 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Falpaca%2F@c1f7bec42e3156d3580d536ab87d099cec7676fa
Security Audit — socket — alpaca