longbridge-fundamentals

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on the longbridge command-line tool to perform data retrieval and analysis.
  • Evidence: Multiple reference files, including references/main-business-analysis.md and references/financial-report.md, instruct the agent to execute shell commands such as 'longbridge business-segments' and 'longbridge financial-report'.
  • Evidence: SKILL.md lists several CLI commands as primary tools for the agent's tasks.
  • [PROMPT_INJECTION]: The skill processes untrusted external data, which represents an indirect prompt injection surface.
  • Evidence: references/corporate-events.md directs the agent to fetch and classify latest news, announcements, and regulatory filings.
  • Evidence: references/main-business-analysis.md suggests using WebSearch to supplement data for industry rankings and market share.
  • [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions for tool maintenance involving remote updates.
  • Evidence: references/main-business-analysis.md explicitly instructs the agent to run 'longbridge update' if subcommands are not recognized. As this tool is provided by the skill author (longbridge), it is categorized as a vendor resource.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 05:13 AM
Security Audit — agent-trust-hub — longbridge-fundamentals