ibkr-api-skill

Warn

Audited by Socket on Sep 17, 2026

3 alerts found:

SecurityAnomalyx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core IBKR purpose aligns with portfolio and trading capabilities, and the PyPI install path for `ib_async` is coherent. The main risk comes from enabling autonomous financial actions and from referencing unofficial community MCP servers—especially a personal archived repo—which can sit between the agent and IBKR and may receive sensitive trading context or credentials.

Confidence: 88%Severity: 74%
AnomalyLOW
reference/trading-patterns.md

The code is intended for legitimate Interactive Brokers trading workflows and contains no apparent malware, credential theft, exfiltration, obfuscation, or sabotage. It does expose live order-placement capability and has significant validation weaknesses, especially incomplete IRA enforcement and incorrect short-sale detection, so it should not be used for live trading without stronger authorization, account-permission checks, and input validation.

Confidence: 98%Severity: 62%
AnomalyLOW
reference/connection-patterns.md

The fragment appears to implement legitimate Interactive Brokers API session and authentication helpers, with no clear evidence of malware or intentional data theft. The explicit verify=False setting is a significant transport-security weakness and should be removed so certificate verification remains enabled. Private-key file permissions, path validation, endpoint allowlisting, and secure token handling should also be reviewed.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 09:58 AM
Package URL
pkg:socket/skills-sh/scientiacapital%2Fskills%2Fibkr-api-skill%2F@7839a28399c33f54f8b31f5c3d2eefe1a6ccb34b635d488206b8b5504a529f67
Security Audit — socket — ibkr-api-skill