Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add faberlens/hardened-skills --skill alpaca-trading-hardenedgit clone --depth 1 https://github.com/faberlens/hardened-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/faberlens/hardened-skills/alpaca-trading-hardened)<a href="https://agentmods.dev/skills/faberlens/hardened-skills/alpaca-trading-hardened"><img src="https://agentmods.dev/badge/skills/faberlens/hardened-skills/alpaca-trading-hardened/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/faberlens/hardened-skills/alpaca-trading-hardened"><img src="https://agentmods.dev/badge/skills/faberlens/hardened-skills/alpaca-trading-hardened.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00096 | $0.03925 |
| Opus 5 | $0.00048 | $0.01962 |
| Sonnet 5 | $0.00019 | $0.00785 |
| Haiku 4.5 | $0.00010 | $0.00392 |
Grade A, and why
alpaca-trading-hardened scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 557 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Alpaca Trading Skill
Execute trades and manage portfolios through the apcacli command-line tool for Alpaca's Trading API.
Overview
You are an expert in using apcacli for command-line stock trading. Your goal is to help users trade stocks, ETFs, options, and crypto efficiently through Alpaca's API while emphasizing safety and best practices.
How to Use This Skill
When helping users with trading tasks:
- Safety First: Always recommend paper trading for new users or when testing
- Verify Commands: Show the exact command before executing trades
- Check Prerequisites: Confirm market hours, account balance, and valid symbols
- Explain Order Types: Help users choose the right order type for their needs
- Risk Management: Suggest stop losses and position sizing
What This Skill Does
apcacli is a Rust-based CLI for interacting with Alpaca's trading platform. It provides:
- Trading: Submit, modify, and cancel orders for stocks, ETFs, options, and crypto
- Portfolio Management: View positions, P/L, and account information
- Market Data: Access asset information and market clock status
- Account Activity: Track trading history and account changes
- Real-time Streaming: Monitor account and trade events
When to Use This Skill
Use this skill when the user wants to:
- Execute trades (buy/sell stocks, ETFs, options, crypto)
- Check portfolio positions and performance
- View or manage orders (open, filled, cancelled)
- Get account balance and buying power
- Access market data and asset information
- Monitor account activity and events
- Check if the market is open
- Set up stop losses or trailing stops
- Automate trading workflows with scripts
Common trigger phrases:
- "Buy 10 shares of AAPL"
- "Show my open positions"
- "What's my account balance?"
- "List all my orders"
- "Cancel order [ID]"
- "Is the market open?"
- "Show my portfolio performance"
- "Set a stop loss on my position"
- "Close all my positions"
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 557 lines · 96 tokens per session scan A bf1604fd0b7c
alpaca-trading-hardened is a skill published in the GitHub repository faberlens/hardened-skills (23 stars, last pushed 4mo ago), licensed MIT. It adds 96 tokens to every session and 3,925 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
risk-metrics-calculation
Calculate portfolio risk metrics including VaR, CVaR, Sharpe, Sortino, and drawdown analysis. Use when measuring portfolio risk, implementing risk limits, or building risk monitoring systems.
paypal-integration
Integrate PayPal payment processing with support for express checkout, subscriptions, and refund management. Use when implementing PayPal payments, processing online transactions, or building e-commerce checkout flows.
stripe-integration
Implement Stripe payment processing for robust, PCI-compliant payment flows including checkout, subscriptions, and webhooks. Use when integrating Stripe payments, building subscription systems, or implementing secure checkout flows.
creating-financial-models
This skill provides an advanced financial modeling suite with DCF analysis, sensitivity testing, Monte Carlo simulations, and scenario planning for investment decisions.
analyzing-financial-statements
\"This skill calculates key financial ratios and metrics from financial statement data for investment analysis\".
floe-guard
Know what every AI call really costs — floe-guard meters STT + TTS + LLM + telephony per call (Pipecat, LiveKit — Python & TypeScript), keeps a live ledger of real spend, and hard-stops the next turn before it crosses a USD ceiling. Free Coverage Score + 7-day history on connect. Use when an agent's spend must be seen…