ib-trailing-stop
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script (
trailing_stop.py) using theuvtool to interact with the Interactive Brokers API on local ports (7496/7497). This is the core functionality intended for the skill.\n- [EXTERNAL_DOWNLOADS]: The skill liststrading-skillsas a dependency, which is an internal library associated with the vendor's toolset.\n- [PROMPT_INJECTION]: The skill ingests position and order data from the Interactive Brokers API (Ingestion) to generate formatted markdown reports and manage orders (Capabilities). This creates a surface for indirect prompt injection via asset names or notes, though the risk is mitigated by the skill's specific purpose and the requirement for explicit execution flags.\n - Ingestion points: Portfolio and order data from Interactive Brokers API.\n
- Boundary markers: Structured JSON output formatted into Markdown reports.\n
- Capability inventory: Order placement and cancellation via the broker API.\n
- Sanitization: Relies on the
trading_skillslibrary and agent-level reporting logic.\n- [SAFE]: The skill implements a 'dry-run' safety mechanism by default; state-changing operations like placing or canceling orders are only performed if the user explicitly provides the--executeflag.\n- [SAFE]: Configuration of sensitive connection details, such as theIB_PORT, is handled via environment variables or.envfiles, which follows security best practices for local secret management.
Audit Metadata