longbridge-investors
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFENO_CODECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [NO_CODE]: The skill consists entirely of instructional prompts in SKILL.md and does not include any accompanying scripts or executable files, reducing the surface area for hidden malicious logic.
- [COMMAND_EXECUTION]: The skill utilizes the
longbridgeCLI to perform data retrieval operations. These commands are limited to fetching financial reports and do not involve system modification or sensitive file access. - [EXTERNAL_DOWNLOADS]: The instructions reference an MCP transport URL (
https://openapi.longbridge.com/mcp) belonging to the official vendor domain. This is used for standard communication between the agent and the vendor's data services. - [SAFE]: No patterns of obfuscation, credential harvesting, or persistence mechanisms were found. The tool operates within its declared scope of financial data analysis using vendor-provided infrastructure.
Audit Metadata