{"data":{"skill":{"slug":"longbridge-longbridge-market-data","name":"longbridge-market-data","icon":"📦","repo":"https://github.com/longbridge/skills/tree/main/skills/longbridge-market-data","status":"approved","author":"longbridge","authorVersion":"1.0.0","skillstoreRevision":2},"audit":{"id":"b4342a62-19a7-4dae-8221-95f646661276","skill_id":"66746cfb-09f5-4a7e-b3c9-91875c9f67c3","version":5,"content_hash":"v3:ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006:b78180a9cba110a9f33504cf85ac55f3b9bb6d504e5e0233bd97c09abbf63339:1a7021e3c1ad92ee9403183ef1010eab5466061bc5ecf4b5da2550776926b89c:736b696c6c732f6c6f6e676272696467652f6c6f6e676272696467652d6d61726b65742d64617461:487e0b0671a022f078146783a1ad5026","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 54 static alerts are false positives caused by Markdown code spans, fenced examples, or finance-domain terms. The skill uses a fixed Longbridge CLI or MCP for its stated purpose; no dynamic shell construction, prompt injection, exfiltration, or system reconnaissance was found. Account-specific IPO and subscription features still require the permissions documented by the skill.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/exchange-rate.md","line_end":25,"line_start":18},{"file":"references/intraday.md","line_end":6,"line_start":6},{"file":"references/intraday.md","line_end":16,"line_start":16},{"file":"references/intraday.md","line_end":37,"line_start":30},{"file":"references/ipo.md","line_end":38,"line_start":31},{"file":"references/market-status.md","line_end":25,"line_start":18},{"file":"references/participants.md","line_end":18,"line_start":6},{"file":"references/participants.md","line_end":25,"line_start":18},{"file":"references/trade-stats.md","line_end":29,"line_start":22},{"file":"references/trades.md","line_end":27,"line_start":6},{"file":"references/trades.md","line_end":34,"line_start":27},{"file":"references/trading.md","line_end":30,"line_start":23},{"file":"SKILL.md","line_end":55,"line_start":55},{"file":"SKILL.md","line_end":57,"line_start":57},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":59,"line_start":59},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":74,"line_start":74},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":79,"line_start":79},{"file":"SKILL.md","line_end":80,"line_start":80},{"file":"SKILL.md","line_end":81,"line_start":81},{"file":"SKILL.md","line_end":95,"line_start":95},{"file":"SKILL.md","line_end":96,"line_start":96},{"file":"SKILL.md","line_end":97,"line_start":97},{"file":"SKILL.md","line_end":102,"line_start":102},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":110,"line_start":110},{"file":"SKILL.md","line_end":111,"line_start":111},{"file":"SKILL.md","line_end":112,"line_start":112},{"file":"SKILL.md","line_end":125,"line_start":116}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":19,"total_lines":996,"audit_model":"codex","audited_at":"2026-07-23T18:09:21.874+00:00","created_at":"2026-07-25T21:21:34.433393+00:00","static_findings":[{"id":"blocker:references/capital.md:48:system-reconnaissance","file":"references/capital.md","pattern":"System reconnaissance","snippet":"If `longbridge` is missing, fall back to MCP. Other stderr messages get relayed verbatim (auth issue","category":"blocker","line_end":48,"severity":"low","line_start":48},{"id":"blocker:references/depth.md:10:system-reconnaissance","file":"references/depth.md","pattern":"System reconnaissance","snippet":"| `brokers`  | Per-level broker_id queue (**HK only**). Tell the user the queue is HK-only when they","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:references/depth.md:21:system-reconnaissance","file":"references/depth.md","pattern":"System reconnaissance","snippet":"5. Render `depth` as a bid / ask table; describe `trades` as a direction summary (buy-dominant / sel","category":"blocker","line_end":21,"severity":"low","line_start":21},{"id":"blocker:references/depth.md:40:system-reconnaissance","file":"references/depth.md","pattern":"System reconnaissance","snippet":"If `longbridge` is missing, fall back to MCP. If stderr surfaces _\"broker queue not supported\"_ / _\"","category":"blocker","line_end":40,"severity":"low","line_start":40},{"id":"external_commands:references/exchange-rate.md:18:ruby-shell-backtick-execution","file":"references/exchange-rate.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":25,"severity":"medium","line_start":18},{"id":"blocker:references/fx-carry.md:25:system-reconnaissance","file":"references/fx-carry.md","pattern":"System reconnaissance","snippet":"7. Assess tail-risk scenarios (rapid JPY strength / EM stress / risk-off unwind).","category":"blocker","line_end":25,"severity":"low","line_start":25},{"id":"external_commands:references/intraday.md:6:ruby-shell-backtick-execution","file":"references/intraday.md","pattern":"Ruby/shell backtick execution","snippet":"Returns: timestamp, price, volume, turnover, `avg_price`. Use `--session all` to include pre-market ","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:references/intraday.md:16:ruby-shell-backtick-execution","file":"references/intraday.md","pattern":"Ruby/shell backtick execution","snippet":"Trade session filter: `intraday` (default) | `all` (includes pre/post market)","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:references/intraday.md:30:ruby-shell-backtick-execution","file":"references/intraday.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":37,"severity":"medium","line_start":30},{"id":"external_commands:references/ipo.md:31:ruby-shell-backtick-execution","file":"references/ipo.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":38,"severity":"medium","line_start":31},{"id":"blocker:references/kline.md:62:system-reconnaissance","file":"references/kline.md","pattern":"System reconnaissance","snippet":"- `Error: invalid symbol` / `param_error` → re-check the `<CODE>.<MARKET>` format.","category":"blocker","line_end":62,"severity":"low","line_start":62},{"id":"external_commands:references/market-status.md:18:ruby-shell-backtick-execution","file":"references/market-status.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":25,"severity":"medium","line_start":18},{"id":"external_commands:references/participants.md:6:ruby-shell-backtick-execution","file":"references/participants.md","pattern":"Ruby/shell backtick execution","snippet":"Use these IDs to interpret results from the `brokers` command.","category":"external_commands","line_end":18,"severity":"medium","line_start":6},{"id":"external_commands:references/participants.md:18:ruby-shell-backtick-execution","file":"references/participants.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":25,"severity":"medium","line_start":18},{"id":"blocker:references/quote.md:77:system-reconnaissance","file":"references/quote.md","pattern":"System reconnaissance","snippet":"| stderr contains `param_error` or \"invalid symbol\" | Re-check the `<CODE>.<MARKET>` format with the","category":"blocker","line_end":77,"severity":"low","line_start":77},{"id":"blocker:references/security-list.md:3:system-reconnaissance","file":"references/security-list.md","pattern":"System reconnaissance","snippet":"Catalog lookups: US overnight-eligible securities, and the HK broker_id → name dictionary.","category":"blocker","line_end":3,"severity":"low","line_start":3},{"id":"blocker:references/security-list.md:19:system-reconnaissance","file":"references/security-list.md","pattern":"System reconnaissance","snippet":"- For broker_id translation, find the matching row instead of dumping the whole directory.","category":"blocker","line_end":19,"severity":"low","line_start":19},{"id":"external_commands:references/trade-stats.md:22:ruby-shell-backtick-execution","file":"references/trade-stats.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":29,"severity":"medium","line_start":22},{"id":"external_commands:references/trades.md:6:ruby-shell-backtick-execution","file":"references/trades.md","pattern":"Ruby/shell backtick execution","snippet":"Returns: timestamp, price, volume, direction (up/down/neutral), `trade_type`. Example: longbridge tr","category":"external_commands","line_end":27,"severity":"medium","line_start":6},{"id":"external_commands:references/trades.md:27:ruby-shell-backtick-execution","file":"references/trades.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":34,"severity":"medium","line_start":27},{"id":"external_commands:references/trading.md:23:ruby-shell-backtick-execution","file":"references/trading.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":30,"severity":"medium","line_start":23},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run `longbridge --help` to list all subcommands. Run `longbridge <cmd> --help` for flags.","category":"external_commands","line_end":55,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `quote` — real-time quote for one or more symbols","category":"external_commands","line_end":57,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `depth` — Level 2 order book (bid/ask ladder)","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `brokers` — broker queue at each price level (HK only)","category":"external_commands","line_end":59,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `trades` — recent tick-by-tick trades","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `intraday` — intraday minute-by-minute price and volume","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `kline` — OHLCV candlestick data or historical date-range","category":"external_commands","line_end":62,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `static` — static reference info (name, listing exchange, lot size, etc.)","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `calc-index` — calculated indexes (PE, PB, turnover rate, DPS rate)","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `capital` — intraday capital distribution or flow time series","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `market-temp` — market sentiment index (0–100)","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `trading` — trading session schedule and trading calendar","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `security-list` — overnight-eligible securities by market","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `participants` — market maker broker IDs and names","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `subscriptions` — active real-time WebSocket subscriptions","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `ah-premium` — A/H premium ratio for dual-listed stocks","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `trade-stats` — price distribution by volume (intraday profile)","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `market-status` — market open/close status for each exchange","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `exchange-rate` — exchange rates for all supported currencies","category":"external_commands","line_end":74,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `ipo` — IPO commands: calendar, subscriptions, us-subscriptions, orders, profit-loss","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `quote`, `depth`, `brokers`, `trades`, `intraday`, `kline`, `static`, `calc-index`, `capital`, `ma","category":"external_commands","line_end":79,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `subscriptions`: Requires active session token","category":"external_commands","line_end":80,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `ipo orders`, `ipo profit-loss`: 🔐 Requires `longbridge auth login` (Trade permission)","category":"external_commands","line_end":81,"severity":"medium","line_start":81},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `command not found: longbridge` | Install longbridge-terminal: `brew tap longbridge/tap && brew in","category":"external_commands","line_end":95,"severity":"medium","line_start":95},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `not logged in` / `unauthorized` | Run `longbridge auth login` |","category":"external_commands","line_end":96,"severity":"medium","line_start":96},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Empty result | \"No data returned — verify the symbol format is `<CODE>.<MARKET>` (e.g. NVDA.US, 70","category":"external_commands","line_end":97,"severity":"medium","line_start":97},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"If `longbridge` binary is unavailable, use the Longbridge MCP server. Discover available tools from ","category":"external_commands","line_end":102,"severity":"medium","line_start":102},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Technical analysis (Ichimoku / SMC / Turtle) | `longbridge-technical` |","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Options or warrants | `longbridge-derivatives` |","category":"external_commands","line_end":109,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Financial statements / fundamentals | `longbridge-fundamentals` |","category":"external_commands","line_end":110,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Analyst ratings / institutional data | `longbridge-research` |","category":"external_commands","line_end":111,"severity":"medium","line_start":111},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Morning briefing / sector rotation / ETF | `longbridge-intel` |","category":"external_commands","line_end":112,"severity":"medium","line_start":112},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":125,"severity":"medium","line_start":116}],"finding_verdicts":[{"id":"blocker:references/capital.md:48:system-reconnaissance","reason":"The line describes fallback behavior when the named Longbridge CLI is unavailable and relays ordinary errors. It does not enumerate system properties or collect host information.","verdict":"false_positive","confidence":0.98},{"id":"blocker:references/depth.md:10:system-reconnaissance","reason":"The line documents an HK-only broker queue field. It contains no host, process, account, or network reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/depth.md:21:system-reconnaissance","reason":"The line explains how to summarize order-book depth and trade direction. This is market-data presentation, not system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/depth.md:40:system-reconnaissance","reason":"The line handles a missing Longbridge CLI and expected broker-support errors. This limited feature check does not inspect broader system state.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:references/exchange-rate.md:18:ruby-shell-backtick-execution","reason":"The backticks format a literal asterisk in copied CLI help text. No Ruby backtick operator, shell substitution, or executable code is present.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/fx-carry.md:25:system-reconnaissance","reason":"The line requests financial tail-risk analysis for currency carry trades. It does not inspect the local system or its configuration.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/intraday.md:6:ruby-shell-backtick-execution","reason":"Backticks mark field and option names inside CLI documentation. They are Markdown formatting and cannot execute commands.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/intraday.md:16:ruby-shell-backtick-execution","reason":"The backticks delimit two allowed session values in help text. There is no shell or Ruby execution context.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/intraday.md:30:ruby-shell-backtick-execution","reason":"The backticks format the stderr prefix character in copied CLI help output. No command substitution or executable Ruby exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/ipo.md:31:ruby-shell-backtick-execution","reason":"The backticks format a literal verbose-output prefix in CLI help text. The Markdown reference contains no executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/kline.md:62:system-reconnaissance","reason":"The line maps known market-data errors to symbol-format guidance. It does not probe operating-system or network details.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/market-status.md:18:ruby-shell-backtick-execution","reason":"The inline backticks format a literal asterisk from Longbridge help output. They are not shell or Ruby execution syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/participants.md:6:ruby-shell-backtick-execution","reason":"The backticks identify the brokers subcommand in prose. The line neither invokes a shell nor constructs a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/participants.md:18:ruby-shell-backtick-execution","reason":"The backticks format the verbose-output prefix documented by the CLI. No executable backtick operator is present.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/quote.md:77:system-reconnaissance","reason":"The line handles a market symbol validation error. It does not collect system, identity, process, or network information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/security-list.md:3:system-reconnaissance","reason":"The line describes public security and broker catalog lookups. These are domain records, not local system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/security-list.md:19:system-reconnaissance","reason":"The line limits broker-directory output to one matching record. This reduces data disclosure and does not inspect system state.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/trade-stats.md:22:ruby-shell-backtick-execution","reason":"The backticks format a literal asterisk in copied CLI help text. The Markdown file does not execute shell or Ruby code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/trades.md:6:ruby-shell-backtick-execution","reason":"The backticks label the trade_type field in command documentation. They are Markdown delimiters, not executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/trades.md:27:ruby-shell-backtick-execution","reason":"The inline backticks format a documented stderr prefix. No Ruby expression, shell expansion, or dynamic execution exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/trading.md:23:ruby-shell-backtick-execution","reason":"The backticks format a literal verbose-output prefix in CLI help. This is inert Markdown text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"Backticks are Markdown delimiters around fixed Longbridge help commands. The line has no Ruby context, shell substitution, or user-controlled command construction.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"The backticks format the quote subcommand in a Markdown heading. They do not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The backticks format the depth subcommand in a Markdown heading. No executable code is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The brokers name appears as inert inline code in a heading. This is not shell or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The trades name is a Markdown code span describing a CLI feature. It is not an executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The intraday name is formatted as inline code in documentation. No command runs from this heading.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The kline name is an inert Markdown code span. There is no shell substitution or Ruby execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The static subcommand is named in a Markdown heading only. The backticks are formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The calc-index name is displayed as inline code. The line contains no executable command expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The capital subcommand is documented in an inert Markdown heading. Backticks do not cause execution here.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The market-temp name is a Markdown code span in a command catalog. It is not shell syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The trading subcommand is only formatted as inline code. No runtime evaluation occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The security-list name appears in a documentation heading. Markdown backticks are inert.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The participants subcommand is described as inline code. The line does not invoke a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The subscriptions name is an inert code span in Markdown documentation. No Ruby or shell execution exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The ah-premium subcommand is only named in a heading. Its backticks are Markdown formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The trade-stats name is rendered as inline code in documentation. It is not executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The market-status subcommand appears in a Markdown code span. No executable context is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The exchange-rate name is documentation text enclosed by Markdown backticks. It cannot execute.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The ipo subcommand is listed as inline code in a heading. This is not Ruby or shell backtick execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The line uses code spans to list public Longbridge subcommands and their access level. It contains no executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The subscriptions name is formatted as inline code while documenting its token requirement. No token is read or command executed by this line.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:81:ruby-shell-backtick-execution","reason":"Backticks format fixed IPO and authentication command names while documenting required permission. There is no shell substitution or dynamic execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:95:ruby-shell-backtick-execution","reason":"The backticks delimit a fixed installation command in a troubleshooting response table. The Markdown does not execute the command or interpolate user input.","verdict":"false_positive","confidence":0.95},{"id":"external_commands:SKILL.md:96:ruby-shell-backtick-execution","reason":"The fixed authentication command is presented as user guidance in inline code. It is not executed through a Ruby backtick operator or command substitution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:97:ruby-shell-backtick-execution","reason":"The backticks format a symbol placeholder in an error message. No command or executable syntax appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:102:ruby-shell-backtick-execution","reason":"The backticks identify the Longbridge binary before a documented MCP fallback. They are Markdown formatting, not execution syntax.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The related skill name is shown as inline code in a routing table. It is not a command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The related derivatives skill name is inert Markdown text. No shell or Ruby evaluation occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"The related fundamentals skill name is formatted as inline code only. It cannot execute.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:111:ruby-shell-backtick-execution","reason":"The related research skill name appears in a Markdown table. It is not executable syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:112:ruby-shell-backtick-execution","reason":"The related intelligence skill name is a Markdown code span. No command execution is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:116:ruby-shell-backtick-execution","reason":"The three backticks open a fenced file-layout example. They are unambiguously Markdown fence syntax, not a Ruby or shell operator.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","subject_content_hash":"b78180a9cba110a9f33504cf85ac55f3b9bb6d504e5e0233bd97c09abbf63339","subject_tree_hash":"1a7021e3c1ad92ee9403183ef1010eab5466061bc5ecf4b5da2550776926b89c","subject_plugin_path":"skills/longbridge/longbridge-market-data","audit_payload_hash":"487e0b0671a022f078146783a1ad5026","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","contentHash":"b78180a9cba110a9f33504cf85ac55f3b9bb6d504e5e0233bd97c09abbf63339","treeHash":"1a7021e3c1ad92ee9403183ef1010eab5466061bc5ecf4b5da2550776926b89c","pluginPath":"skills/longbridge/longbridge-market-data","auditPayloadHash":"487e0b0671a022f078146783a1ad5026"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/longbridge-longbridge-market-data/audits/5/attestation","status":"superseded"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"superseded","verificationState":"not_verified"},"isLatest":false}}