longbridge-research

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to orchestrate calls to the "longbridge" CLI to retrieve financial metrics, analyst ratings, and corporate data. This behavior is consistent with its stated purpose as a research tool. No malicious patterns like prompt injection, obfuscation, or persistence mechanisms were detected.
  • [COMMAND_EXECUTION]: Multiple reference files (e.g., "references/company-profile.md", "references/stock-research.md") define workflows that execute various subcommands of the "longbridge" utility. These commands are used solely for data retrieval in JSON or pretty-print formats and do not involve shell piping or arbitrary input execution.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes WebSearch as a fallback mechanism for data points not provided by the CLI, such as DeFi metrics (from DefiLlama, CoinGecko) and HK IPO prospectus details (from HKEXnews). These targets are well-known, reputable financial information services and the behavior is clearly documented in the reference files.
  • [DATA_EXPOSURE]: While the skill accesses portfolio and position data (via "longbridge portfolio" and "longbridge positions"), this access is restricted to the financial planning and calendar tracking modules and requires explicit user authorization via the terminal's authentication flow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 12:30 PM
Security Audit — agent-trust-hub — longbridge-research