longbridge-watchlist
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using the
longbridgeCLI tool to interact with financial services. These commands includelongbridge watchlist,longbridge alert, andlongbridge sharelistto perform operations like creating, deleting, and modifying user data. - [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it accepts user-provided parameters (such as stock symbols, group names, and alert prices) and interpolates them into shell commands.
- Ingestion points: User-supplied strings for ticker symbols (e.g., TSLA.US), watchlist group names, and alert parameters in
references/alert.md,references/watchlist.md, andreferences/sharelist.md. - Boundary markers: The skill enforces a mandatory 'Two-step protocol' which requires the agent to preview the intended action and wait for explicit user confirmation ('yes', 'confirm', etc.) before executing any mutation.
- Capability inventory: Shell command execution via the
longbridgeCLI tool for managing account-level stock data. - Sanitization: The instructions emphasize verifying IDs and symbols before execution, and the confirmation protocol serves as a manual sanitization gate to prevent unintended command execution.
- [METADATA_POISONING]: There is a discrepancy in the skill's metadata; the frontmatter in
SKILL.mdspecifiestier: read, whereas the skill's primary functionality includes mutating operations such as creating and deleting records. This inconsistency could lead to a misunderstanding of the skill's actual permissions and risk profile.
Audit Metadata