longbridge-positions
Pass
Audited by Gen Agent Trust Hub on May 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is authored by the service provider (longbridge) and interacts exclusively with the vendor's official infrastructure through the
longbridgeCLI and MCP tools. No unauthorized data exfiltration or third-party connections were found. - [COMMAND_EXECUTION]: Shell commands are restricted to the primary purpose of the skill: managing and querying account information via the
longbridgeutility. - [DATA_EXPOSURE]: The skill handles sensitive financial information but includes explicit privacy instructions for the agent, advising it to confirm with the user before displaying exact figures if a third party might be observing. This is a security best practice for handling private data.
- [CREDENTIALS_UNSAFE]: Authentication is managed through a secure login flow (
longbridge auth login), preventing the need for hardcoded credentials or unsafe secret storage within the skill itself.
Audit Metadata