Back to skill

Security audit

Alpaca Trading

Security checks for vulnerabilities and agentic risk

Overview

This Alpaca trading skill is mostly coherent, but it can place or cancel live financial orders with bypassable or missing confirmations.

Review before installing if you may connect live Alpaca credentials. Prefer paper trading, avoid using --force in live mode, confirm any generated order or cancel command yourself, secure ~/.openclaw/credentials/alpaca.json with restrictive permissions, and install alpaca-py only from a trusted, reviewed version.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
scripts/alpaca_cli.py:32
Finding

Unpinned installation guidance for a security-sensitive trading dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/alpaca_cli.py:276
Finding

Force option bypasses live-trading confirmations and multiple order safeguards

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/alpaca_cli.py:75
Finding

Plaintext trading credential file is used without permission validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api.md (reported line 70)May include surrounding context.

md
### GET /v2/orders/{order_id}
Get order by ID.

### DELETE /v2/orders/{order_id}
Cancel order.

### DELETE /v2/orders

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

DELETE /v2/orders cancels all orders in an account, making it a highly destructive operation in a live-trading context. In an agent skill that may act on natural-language instructions, exposing bulk cancellation without strong confirmation and environment safeguards materially increases the risk of accidental or prompt-induced financial harm.

Content

Scanner excerpt · references/api.md (reported line 73)May include surrounding context.

md
### DELETE /v2/orders/{order_id}
Cancel order.

### DELETE /v2/orders
Cancel all orders.

## Order Types

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api.md (reported line 122)May include surrounding context.

md
### POST /v2/watchlists/{watchlist_id}
Add symbol to watchlist.

### DELETE /v2/watchlists/{watchlist_id}
Delete watchlist.

## Rate Limits

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill exposes sensitive capabilities including environment access for API keys, file writes for local persistence, and network access for trading/API calls, but it does not declare any explicit tool scope or permission boundaries. In a trading skill, this increases the chance of unintended credential use, unauthorized external requests, or state-changing actions being invoked without clear policy enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use the skill when a user asks about stock prices, wants to buy or sell securities, check portfolio, or manage trades, which is broad enough to activate trade-capable functionality from ambiguous financial queries. Because the skill can place real orders, overly permissive routing raises the risk of accidental invocation of high-impact actions in response to loosely related prompts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
72% confidence
Finding

The skill documents persistent watchlist and alert management features, and alerts are stored on disk, which introduces session persistence and retained state across runs. In a financial context, persistent state can be abused or become stale, causing unintended notifications, privacy leakage about user interests, or actions based on outdated assumptions if later automation consumes that state.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

Watchlist

bash
python3 scripts/alpaca_cli.py watchlist list
python3 scripts/alpaca_cli.py watchlist create "Tech Stocks" AAPL,MSFT,GOOGL
python3 scripts/alpaca_cli.py watchlist add WATCHLIST_ID NVDA
python3 scripts/alpaca_cli.py watchlist delete WATCHLIST_ID

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file describes placing orders and canceling one or all orders, which can directly affect user assets and system state. The section provides endpoint mechanics but does not include any warning or caution about live trading risk, irreversible execution, or the need to verify whether the user is using paper versus live trading.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/alpaca_cli.py (reported line 93)May include surrounding context.

python
if not api_key or not secret_key:
        print("Error: Alpaca credentials not found.")
        print("Set ALPACA_API_KEY and ALPACA_SECRET_KEY environment variables,")
        print("or create ~/.openclaw/credentials/alpaca.json")
        sys.exit(1)
    
    return api_key, secret_key, paper

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Cancelling all open orders is a destructive trading action that executes immediately when the user passes 'all', with no confirmation prompt or dry-run summary. In a trading skill context, accidental invocation or prompt-manipulated invocation could disrupt intended trades, cause missed executions, and create financial loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Deleting a watchlist is a destructive remote account action, but the function performs it immediately without warning or confirmation. While lower impact than order placement or cancellation, it can still remove user-curated data and be abused through accidental or manipulated tool use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The clear action overwrites the entire local alerts file with an empty set without any confirmation, making accidental data loss easy. Although this affects local state rather than trading positions directly, it can silently remove monitoring important to the user's trading workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes using Alpaca for market data, trading, portfolio management, and account info, but the code also creates a separate local alerting subsystem backed by a file in ~/.openclaw/data and a check mode intended for scheduled execution. That is additional behavior not mentioned in the manifest and is not an obvious Alpaca API implementation detail.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest lists market data, orders, positions, portfolio management, and account info, but does not mention creating, modifying, or deleting watchlists. Watchlist administration is a meaningful user-facing capability beyond the stated description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.