Back to skill

Security audit

Alpaca Trading

Security checks for vulnerabilities and agentic risk

Overview

This Alpaca trading skill is transparent about its purpose, but it gives an agent direct credentialed power to trade, cancel orders, and close positions with weak scoping around destructive actions and API destinations.

Install only if you are comfortable giving an agent access to your Alpaca account. Prefer paper-trading keys, keep live keys separate, verify APCA_API_BASE_URL and APCA_DATA_API_BASE_URL before every use, and require explicit human confirmation before any order placement, option exercise, cancellation, account-configuration change, or position close, especially cancel-all or close-all commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/alpaca.sh:24
Finding

Unrestricted API Base URL Can Expose Alpaca Credentials and Trading Data

Content
View full analysis

Vulnerability Details

File Location: scripts/alpaca.sh, lines 24–47
Vulnerability Type: Unvalidated credential-bearing request destination
Risk Level: High

Vulnerable Code

bash
# --- Base URL resolution ---
# ALPACA_DATA=1 → market data API; otherwise trading API
if [[ "${ALPACA_DATA:-}" == "1" ]]; then
  BASE_URL="${APCA_DATA_API_BASE_URL:-https://data.alpaca.markets}"
else
  BASE_URL="${APCA_API_BASE_URL:-https://paper-api.alpaca.markets}"
fi

URL="${BASE_URL}${ENDPOINT}"

# --- Build curl args ---
CURL_ARGS=(
  -s -w '\n%{http_code}'
  -X "$METHOD"
  -H "APCA-API-KEY-ID: ${APCA_API_KEY_ID}"
  -H "APCA-API-SECRET-KEY: ${APCA_API_SECRET_KEY}"
  -H "Accept: application/json"
)

if [[ -n "$BODY" ]]; then
  CURL_ARGS+=(-H "Content-Type: application/json" -d "$BODY")
fi

# --- Execute ---
RESPONSE=$(curl "${CURL_ARGS[@]}" "$URL")

Technical Analysis

The wrapper accepts APCA_API_BASE_URL and APCA_DATA_API_BASE_URL directly from the process environment without validating the URL scheme, hostname, port, or user information. It then attaches the Alpaca API key and secret to every request sent to the resulting URL.

Consequently, anyone capable of influencing the wrapper's environment can redirect authenticated requests to an arbitrary server. Non-HTTPS destinations are also accepted, allowing credentials and request content to be transmitted without transport encryption.

Shell command injection is not established here because the URL and other arguments are passed through Bash arrays and quoted expansions. The vulnerability is instead an insecure trust-boundary decision: an untrusted or incorrectly configured destination receives sensitive authentication headers.

Attack Path

  1. An attacker compromises a launcher, shell profile, automation configuration, or other mechanism capable of setting process environment variables.
  2. The attacker sets `APCA_API_BASE_ ...[truncated 1268 chars]
Remediation
View remediation

Remediation Suggestions

  1. Strictly allowlist the expected HTTPS origins:

    • https://paper-api.alpaca.markets
    • https://api.alpaca.markets
    • https://data.alpaca.markets
  2. Parse and validate each configured URL before constructing requests. Reject:

    • Any scheme other than HTTPS.
    • Hosts outside the explicit allowlist.
    • Embedded user information.
    • URL fragments.
    • Unexpected ports.
    • Malformed URLs and ambiguous hostname representations.
  3. Enforce endpoint separation:

    • Trading requests should only use an approved trading host.
    • Market-data requests should only use the approved data host.
  4. If custom endpoints are needed for development, require an explicit unsafe-development flag and prevent real Alpaca credentials from being attached to those requests. Use isolated test credentials instead.

  5. Fail closed with a clear error before invoking curl whenever URL validation fails.

  6. Add automated tests covering hostile configurations such as HTTP URLs, look-alike domains, user-information syntax, unexpected ports, and attacker-controlled hosts.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

This documents a destructive order-cancellation endpoint that can cancel a specific order through a shell-enabled helper. In an agent setting, if user intent or parameters are misinterpreted, the skill can perform irreversible account actions affecting live or paper orders; the presence of shell execution and authenticated API access makes this materially sensitive.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

alpaca GET /v2/orders alpaca GET /v2/orders/ORDER_ID alpaca PATCH /v2/orders/ORDER_ID '{"qty":"20","limit_price":"190.00"}' alpaca DELETE /v2/orders/ORDER_ID alpaca DELETE /v2/orders # cancel ALL

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The bulk cancel-all-orders endpoint is especially dangerous because a single invocation can affect every open order in the account. In this skill context, that creates high operational risk if the agent is prompted ambiguously, tricked via prompt injection, or switched to a live endpoint after confirmation fatigue.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

alpaca GET /v2/orders/ORDER_ID alpaca PATCH /v2/orders/ORDER_ID '{"qty":"20","limit_price":"190.00"}' alpaca DELETE /v2/orders/ORDER_ID alpaca DELETE /v2/orders # cancel ALL

text

### Orders — Options

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

Closing a position via DELETE is a state-changing trading action that can liquidate holdings and realize gains or losses. In a shell-driven agent workflow, misuse of the symbol parameter or mistaken invocation could trigger unauthorized or unintended liquidation, which is more serious in a brokerage context than in a generic CRUD API.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

alpaca GET '/v2/positions?asset_class=us_option' # options only alpaca GET /v2/positions/AAPL # single equity alpaca GET /v2/positions/NVDA260417C00220000 # single option alpaca DELETE /v2/positions/AAPL # close alpaca DELETE '/v2/positions/AAPL?qty=5' # close partial alpaca DELETE '/v2/positions?cancel_orders=true' # close ALL

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

Partial close operations are still sensitive because an attacker or confused workflow can alter the qty parameter to sell more than intended or target the wrong symbol. Because the skill directly templates authenticated API paths and query parameters, parameter abuse can translate into real financial actions with immediate account impact.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

alpaca GET /v2/positions/AAPL # single equity alpaca GET /v2/positions/NVDA260417C00220000 # single option alpaca DELETE /v2/positions/AAPL # close alpaca DELETE '/v2/positions/AAPL?qty=5' # close partial alpaca DELETE '/v2/positions?cancel_orders=true' # close ALL

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This endpoint can close all positions and optionally cancel orders, making it the most dangerous action in the file. In the context of a trading skill with possible live-account access, a single mistaken or manipulated call could unwind an entire portfolio and disrupt all active trading, causing substantial financial harm.

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

alpaca GET /v2/positions/NVDA260417C00220000 # single option alpaca DELETE /v2/positions/AAPL # close alpaca DELETE '/v2/positions/AAPL?qty=5' # close partial alpaca DELETE '/v2/positions?cancel_orders=true' # close ALL

text

### Market data — Stocks

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

A direct cancel-order command template is exposed with a free-form order identifier and no mention of validation or confirmation. In an agent/tooling setting, this enables parameter abuse or accidental cancellation of legitimate open orders, which can disrupt execution strategy and cause financial loss.

Content

Scanner excerpt · references/api.md (reported line 117)May include surrounding context.

md
alpaca PATCH /v2/orders/ORDER_ID '{"qty":"20","limit_price":"190.00"}'

# Cancel order
alpaca DELETE /v2/orders/ORDER_ID

# Cancel ALL open orders
alpaca DELETE /v2/orders

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The bulk command to cancel all open orders is highly destructive and is presented as a simple one-liner without any safety interlock. If invoked mistakenly or through prompt manipulation, it can wipe out an account's pending execution plan immediately.

Content

Scanner excerpt · references/api.md (reported line 120)May include surrounding context.

alpaca DELETE /v2/orders/ORDER_ID

Cancel ALL open orders

alpaca DELETE /v2/orders

text

#### Order fields reference

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file shows option exercise, position liquidation, and bulk close commands without explicit caution that these actions may be irreversible, time-sensitive, or financially harmful. In a trading skill, these are especially dangerous because an agent could translate user discussion into immediate sell/close/exercise actions with real portfolio impact.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This endpoint closes an entire position at market and is presented without safeguards, making it easy for an agent or user to liquidate holdings unintentionally. Because it affects real portfolio assets and may execute at unfavorable market prices, misuse can produce immediate financial damage.

Content

Scanner excerpt · references/api.md (reported line 227)May include surrounding context.

md
alpaca GET /v2/positions/NVDA260417C00220000

# Close a position (market sell all)
alpaca DELETE /v2/positions/AAPL
# Close partial (by qty)
alpaca DELETE '/v2/positions/AAPL?qty=5'
# Close partial (by percentage)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The partial-close-by-quantity example accepts a numeric parameter that could be manipulated, misparsed, or inferred incorrectly by an agent. In a brokerage context, quantity mistakes directly alter the user's holdings and can result in unauthorized or excessive liquidation.

Content

Scanner excerpt · references/api.md (reported line 229)May include surrounding context.

md
# Close a position (market sell all)
alpaca DELETE /v2/positions/AAPL
# Close partial (by qty)
alpaca DELETE '/v2/positions/AAPL?qty=5'
# Close partial (by percentage)
alpaca DELETE '/v2/positions/AAPL?percentage=50'

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Percentage-based liquidation is especially error-prone because natural-language requests can be interpreted loosely and because percentages may have outsized real effects. Presenting this as an immediate DELETE template without confirmation increases the risk of accidental portfolio changes.

Content

Scanner excerpt · references/api.md (reported line 231)May include surrounding context.

md
# Close partial (by qty)
alpaca DELETE '/v2/positions/AAPL?qty=5'
# Close partial (by percentage)
alpaca DELETE '/v2/positions/AAPL?percentage=50'

# Close ALL positions
alpaca DELETE '/v2/positions?cancel_orders=true'

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The command to close all positions, optionally canceling orders, is an account-wide destructive action with severe financial consequences and no documented confirmation or scoping. In the context of a trading skill, this is one of the most dangerous actions because a single mistaken invocation can fully unwind a portfolio.

Content

Scanner excerpt · references/api.md (reported line 234)May include surrounding context.

alpaca DELETE '/v2/positions/AAPL?percentage=50'

Close ALL positions

alpaca DELETE '/v2/positions?cancel_orders=true'

text

### Assets

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api.md (reported line 281)May include surrounding context.

md
alpaca POST /v2/watchlists/WATCHLIST_ID '{"symbol":"AMZN"}'

# Remove symbol from watchlist
alpaca DELETE /v2/watchlists/WATCHLIST_ID/SYMBOL

# Delete watchlist
alpaca DELETE /v2/watchlists/WATCHLIST_ID

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api.md (reported line 284)May include surrounding context.

alpaca DELETE /v2/watchlists/WATCHLIST_ID/SYMBOL

Delete watchlist

alpaca DELETE /v2/watchlists/WATCHLIST_ID

text

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The wrapper exposes arbitrary HTTP method and path control, including destructive operations like DELETE and trade placement endpoints, with no confirmation, policy checks, or parameter restrictions. In an agent setting, this makes prompt-driven misuse easy: a user can induce order placement, cancellation, options exercise, or other irreversible account actions if the skill is invoked without a separate authorization layer.

Content

Scanner excerpt · scripts/alpaca.sh (reported line 7)May include surrounding context.

sh
# Examples:
#   alpaca GET /v2/account
#   alpaca POST /v2/orders '{"symbol":"AAPL","qty":"10","side":"buy","type":"market","time_in_force":"day"}'
#   alpaca DELETE /v2/orders/ORDER_ID
#   ALPACA_DATA=1 alpaca GET '/v2/stocks/AAPL/quotes/latest'
set -euo pipefail

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly documents switching from paper trading to live trading by changing the API base URL, but it does not present a clear warning that this enables real-money transactions with irreversible financial consequences. In a trading skill, that omission materially increases the chance of accidental live trades by users or downstream agents who may follow setup instructions mechanically.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill exposes shell-capable behavior via curl/jq but does not declare any explicit tool scope or allowed-tools boundary. That omission weakens defense-in-depth because an agent may invoke shell access more broadly than intended, increasing the chance of unintended command execution or misuse of API credentials during trading actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger text is very broad and includes common financial terms like buy, sell, quote, positions, and market data, making accidental invocation plausible. In a trading skill, unintended activation is risky because it can expose account data or lead to order-preparation/execution flows in contexts where the user did not actually intend to use Alpaca.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This section provides numerous live trading and account-configuration examples, including order placement and account setting changes, without any explicit warning that these actions can affect real funds or modify brokerage settings. In an agent context, examples often become reusable action templates, so omission of safety gating materially increases the risk of accidental or unauthorized execution.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This script transmits highly sensitive Alpaca API credentials in HTTP headers to a user-controlled URL assembled from environment variables and an unvalidated endpoint path. If APCA_API_BASE_URL or APCA_DATA_API_BASE_URL is changed to an attacker-controlled host, or if the wrapper is invoked on unintended endpoints, the credentials can be exfiltrated and then used to place trades, access portfolio data, or perform account actions.

Content

Scanner excerpt · scripts/alpaca.sh (reported line 31)May include surrounding context.

sh
URL="${BASE_URL}${ENDPOINT}"

# --- Build curl args ---
CURL_ARGS=(
  -s -w '\n%{http_code}'
  -X "$METHOD"

Static analysis

No suspicious patterns detected.