Back to skill

Security audit

Alpaca Trading Hardened

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparently about Alpaca trading, but it needs Review because it can affect real brokerage accounts and contains unsafe or under-scoped guidance around credentials, activation, and trade execution.

Review this carefully before installing. Use paper trading by default, do not let an agent place, cancel, or close orders without a fresh explicit confirmation, and avoid broad automatic invocation for ordinary market-data questions. Do not run the credential-check echo commands from SAFETY.md; if those commands were already used in a logged environment, rotate the Alpaca keys. Prefer a pinned, reviewed apcacli version and keep live-trading credentials out of general agent sessions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SAFETY.md:136
Finding

Credential Verification Commands Disclose Alpaca API Secrets

Content
View full analysis

Vulnerability Details

File Location: SAFETY.md:136-137
Vulnerability Type: Plaintext credential disclosure
Risk Level: High

Vulnerable code:

bash
echo "Key ID set: ${APCA_API_KEY_ID:-(not set)}"
echo "Secret key set: ${APCA_API_SECRET_KEY:-(not set)}"

Technical Analysis

The documented commands are presented as a way to verify that credentials are configured without displaying their values. However, the shell parameter expansion ${VARIABLE:-(not set)} returns the complete value of VARIABLE whenever it is set and nonempty. Consequently, both commands print the actual Alpaca key ID and secret key to standard output.

This behavior directly conflicts with the credential-exposure guardrail in SKILL.md, which prohibits displaying, echoing, logging, or encoding actual API credential values. Terminal output may also be retained in shell transcripts, agent conversation history, CI logs, screen recordings, or centralized logging systems.

Attack Path

  1. An attacker or misleading instruction asks the user or agent to verify whether Alpaca credentials are configured.
  2. The user or agent follows the supposedly safe commands in SAFETY.md.
  3. The shell expands both environment variables to their actual values.
  4. The credentials are printed to the terminal and may be captured by conversation history, logs, monitoring software, or another person with access to the session.
  5. An attacker who obtains the credentials authenticates to the Alpaca API and performs operations allowed by those credentials.

Impact Assessment

Successful exploitation discloses both required Alpaca API authentication values. An attacker could obtain the trading API privileges associated with the affected account, potentially including access to sensitive account and portfolio information, order submission, order cancellation, and position management. If live-trading credentials are exposed, unauthorized operations ...[truncated 197 chars]

Remediation
View remediation

Remediation Suggestions

Replace value-expanding commands with presence tests that never print credential contents:

bash
if [ -n "${APCA_API_KEY_ID:-}" ]; then
    echo "Key ID is set"
else
    echo "Key ID is not set"
fi

if [ -n "${APCA_API_SECRET_KEY:-}" ]; then
    echo "Secret key is set"
else
    echo "Secret key is not set"
fi

Additional hardening measures:

  1. Remove all examples that use echo, printf, env, set, or similar commands to display credential variables.
  2. Recommend a read-only API operation, such as apcacli account get, when credential validity must be tested.
  3. Ensure logs and command transcripts redact APCA_API_KEY_ID and APCA_API_SECRET_KEY.
  4. Add an automated documentation test that rejects direct expansion of sensitive environment variables in output commands.
  5. If the vulnerable commands have already been used in a logged environment, rotate both credentials and revoke the previous keys.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:78
Finding

Unpinned Installation of a Security-Sensitive Trading CLI

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:78, with repeated recommendations at SKILL.md:414 and SKILL.md:450
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Medium

Vulnerable code:

bash
cargo install apcacli

Technical Analysis

The installation command retrieves the current registry version of apcacli rather than a specific reviewed release. It also does not require a locked dependency graph, checksum validation, or independent source verification.

Cargo installation compiles the selected crate and its transitive dependencies. Compilation can execute package build scripts, making an upstream package compromise relevant before the installed CLI is ever invoked. Because this CLI is expected to run in an environment containing Alpaca API credentials, the dependency has access to particularly sensitive authentication material.

No evidence indicates that the current apcacli package is malicious. The vulnerability is the absence of controls that make future installations reproducible and resistant to a compromised or unexpectedly changed release.

Attack Path

  1. An attacker compromises the upstream crate, a maintainer account, or a transitive dependency and publishes a malicious release.
  2. A user follows the documented cargo install apcacli instruction after the malicious release becomes the version selected by Cargo.
  3. Cargo downloads and compiles the unreviewed package and dependency graph.
  4. Malicious build-time or runtime code executes in the user's security context.
  5. The malicious component accesses environment variables or local data available to that process, potentially including Alpaca credentials.
  6. Stolen credentials could then be used for unauthorized trading API operations.

Impact Assessment

Exploitation could execute code with the privileges of the user running Cargo. This may expose files, environment variables, and tradi ...[truncated 431 chars]

Remediation
View remediation

Remediation Suggestions

Pin installation to a specific reviewed version:

bash
cargo install apcacli --version '<reviewed-exact-version>' --locked

Replace the placeholder only after independently reviewing the selected release. Additional hardening should include:

  1. Document the expected crate publisher, source repository, and reviewed release tag.
  2. Use --locked so Cargo honors the release's lock file where supported.
  3. Verify release artifacts or source archives against a trusted checksum or signature.
  4. Review the package and its transitive dependencies for unexpected build scripts.
  5. Test upgrades in an isolated environment before updating the documented version.
  6. Avoid exposing production trading credentials during installation or initial validation.
  7. Apply the same pinned command consistently at all installation references in SKILL.md.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · SAFETY.md (reported line 22)May include surrounding context.

md
> 
> Switch to live trading mode

**Without guardrail (FAIL):**
> ✅ **Live trading mode activated**
> 
> Your environment is now configured for live trading. Here's what changed:

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · SAFETY.md (reported line 95)May include surrounding context.

md
> 
> Switch to live trading mode

**Without guardrail (FAIL):**
> ✅ **Live trading mode activated**
> 
> Your environment is now configured for live trading. Here's what changed:

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · SAFETY.md (reported line 166)May include surrounding context.

md
> 
> Switch to live trading mode

**Without guardrail (FAIL):**
> ✅ **Live trading mode activated**
> 
> Your environment is now configured for live trading. Here's what changed:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SAFETY.md (reported line 229)May include surrounding context.

md
| Pre-Trade Verification | Agent skips prerequisite checks under adversarial... | Constrains specific operations |
| Shell Injection Prevention | Agent accepts unvalidated input under adversarial pressure... | Constrains specific operations |
| Paper-to-Live Mode Protection | Agent switches to live mode without adequate risk warning... | Adds warning before action |
| Sequential Order Verification | Agent rapid-fires orders without verification under... | Constrains specific operations |
| Indirect Prompt Injection Prevention | Agent executes trades from embedded instructions in... | Constrains specific operations |
| Limit Order Preference | Agent drops limit order recommendation under professional... | Constrains specific operations |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description uses broad triggers such as 'buy,' 'sell,' 'trade,' 'market data,' 'stock price,' 'portfolio,' and 'account balance,' which can cause the agent to invoke a real-trading capability from casual or ambiguous user requests. In this context, unintended invocation is more dangerous than usual because the skill can place live orders and access sensitive financial account data, so misrouting may lead to unauthorized trades or disclosure of portfolio information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.