longbridge-watchlist

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the longbridge CLI tool to interact with financial services. These commands include longbridge watchlist, longbridge alert, and longbridge sharelist to perform operations like creating, deleting, and modifying user data.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it accepts user-provided parameters (such as stock symbols, group names, and alert prices) and interpolates them into shell commands.
  • Ingestion points: User-supplied strings for ticker symbols (e.g., TSLA.US), watchlist group names, and alert parameters in references/alert.md, references/watchlist.md, and references/sharelist.md.
  • Boundary markers: The skill enforces a mandatory 'Two-step protocol' which requires the agent to preview the intended action and wait for explicit user confirmation ('yes', 'confirm', etc.) before executing any mutation.
  • Capability inventory: Shell command execution via the longbridge CLI tool for managing account-level stock data.
  • Sanitization: The instructions emphasize verifying IDs and symbols before execution, and the confirmation protocol serves as a manual sanitization gate to prevent unintended command execution.
  • [METADATA_POISONING]: There is a discrepancy in the skill's metadata; the frontmatter in SKILL.md specifies tier: read, whereas the skill's primary functionality includes mutating operations such as creating and deleting records. This inconsistency could lead to a misunderstanding of the skill's actual permissions and risk profile.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — longbridge-watchlist