longbridge-fundamentals

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill follows established patterns for AI agent extensions, providing clear routing logic and triggers for financial analysis. All referenced URLs point to the official GitHub repository for the Longbridge service.
  • [COMMAND_EXECUTION]: The skill invokes the longbridge CLI to retrieve financial statements, valuations, and corporate data. These commands represent the primary, intended purpose of the skill and do not require elevated privileges.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external financial data, which presents a potential surface for indirect injection.
  • Ingestion points: Financial reports, operating reviews, and business segment data returned by the longbridge CLI.
  • Boundary markers: The skill does not explicitly define delimiters for external data within the prompt instructions.
  • Capability inventory: CLI commands for data retrieval; no dangerous file-write or unrestricted network operations are exposed.
  • Sanitization: No explicit sanitization of tool output is defined in the SKILL.md file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:27 PM
Security Audit — agent-trust-hub — longbridge-fundamentals