ibkr-api-skill
Audited by Socket on Sep 17, 2026
3 alerts found:
SecurityAnomalyx2SUSPICIOUS: The core IBKR purpose aligns with portfolio and trading capabilities, and the PyPI install path for `ib_async` is coherent. The main risk comes from enabling autonomous financial actions and from referencing unofficial community MCP servers—especially a personal archived repo—which can sit between the agent and IBKR and may receive sensitive trading context or credentials.
The code is intended for legitimate Interactive Brokers trading workflows and contains no apparent malware, credential theft, exfiltration, obfuscation, or sabotage. It does expose live order-placement capability and has significant validation weaknesses, especially incomplete IRA enforcement and incorrect short-sale detection, so it should not be used for live trading without stronger authorization, account-permission checks, and input validation.
The fragment appears to implement legitimate Interactive Brokers API session and authentication helpers, with no clear evidence of malware or intentional data theft. The explicit verify=False setting is a significant transport-security weakness and should be removed so certificate verification remains enabled. Private-key file permissions, path validation, endpoint allowlisting, and secure token handling should also be reviewed.