alpaca-mcp-server-trading
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill enables an AI agent to perform high-capability financial actions, such as executing trades and managing portfolios, based on natural language input. This creates an attack surface where malicious instructions embedded in untrusted data (e.g., files, web pages, or code comments processed by the agent) could potentially trigger unintended financial transactions.
- Ingestion points: Natural language input processed by the AI assistant or IDE (Claude, Cursor, etc.).
- Boundary markers: None defined; the skill does not specify delimiters or instructions to ignore embedded commands in the processed data.
- Capability inventory: Tools for placing market/limit orders, cancelling orders, and managing positions across stocks and cryptocurrency.
- Sanitization: Not specified in the documentation; relies on the underlying platform's safety guardrails.
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and execute external code using the
uvxpackage manager (alpaca-mcp-server) and to clone a repository from GitHub (alpacahq/alpaca-mcp-server). These resources originate from a well-known service provider (Alpaca) and are documented neutrally.
Audit Metadata