{"data":{"skill":{"slug":"longbridge-longbridge-portfolio","name":"longbridge-portfolio","icon":"📦","repo":"https://github.com/longbridge/skills/tree/main/skills/longbridge-portfolio","status":"approved","author":"longbridge","authorVersion":"1.0.0","skillstoreRevision":2},"audit":{"id":"411e47fa-fef6-43f3-85db-3829cf1ae2c0","skill_id":"70ea85d5-13e5-4614-8acd-1cf6570b94e1","version":5,"content_hash":"v3:ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006:b3e3beeaf9a0499fd000d7a857d13f83e3dbc779f46a21673690f64b020745ec:eee64b7768ebdfeece30f6485753a4eb8ee761a4b4888ef882f07f56161bc00f:736b696c6c732f6c6f6e676272696467652f6c6f6e676272696467652d706f7274666f6c696f:4475bccb652774177eda8d29ce48b5b9","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 57 static alerts are false positives caused by Markdown backticks or ordinary clarification text; the cited lines contain no Ruby execution, shell substitution, or system reconnaissance. However, SKILL.md declares a read tier and default installation while exposing real-money order and DCA mutations. Publication should require corrected metadata and clear installation warnings for Trade permission and financial side effects.","remediation":[{"issue":"The read-tier and default-install metadata conflicts with real-money mutation capabilities.","severity":"high","suggestion":"Set the tier to the appropriate mutating classification and disable default installation for a skill that can place or alter brokerage orders."},{"issue":"Order mutations have a shorter confirmation policy than recurring-investment mutations.","severity":"medium","suggestion":"Require a separate preview turn with symbol, side, quantity, price, and order identifier before every buy, sell, cancel, or replace action."},{"issue":"Trade permission exposes sensitive account data and enables financial mutations.","severity":"medium","suggestion":"Show an installation disclosure listing accessed account data, required permissions, and the real-money effects of order and DCA commands."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"references/assets.md","line_end":6,"line_start":6},{"file":"references/assets.md","line_end":30,"line_start":23},{"file":"references/bank-cards.md","line_end":25,"line_start":18},{"file":"references/cash-flow.md","line_end":6,"line_start":6},{"file":"references/cash-flow.md","line_end":31,"line_start":24},{"file":"references/fund-positions.md","line_end":6,"line_start":6},{"file":"references/fund-positions.md","line_end":25,"line_start":18},{"file":"references/margin-ratio.md","line_end":6,"line_start":6},{"file":"references/margin-ratio.md","line_end":29,"line_start":22},{"file":"references/max-qty.md","line_end":6,"line_start":6},{"file":"references/max-qty.md","line_end":40,"line_start":33},{"file":"references/order.md","line_end":46,"line_start":39},{"file":"references/portfolio.md","line_end":8,"line_start":8},{"file":"references/portfolio.md","line_end":33,"line_start":26},{"file":"references/positions.md","line_end":6,"line_start":6},{"file":"references/positions.md","line_end":25,"line_start":18},{"file":"references/statement.md","line_end":6,"line_start":6},{"file":"references/statement.md","line_end":41,"line_start":34},{"file":"SKILL.md","line_end":56,"line_start":56},{"file":"SKILL.md","line_end":58,"line_start":58},{"file":"SKILL.md","line_end":59,"line_start":59},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":61,"line_start":61},{"file":"SKILL.md","line_end":62,"line_start":62},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66},{"file":"SKILL.md","line_end":67,"line_start":67},{"file":"SKILL.md","line_end":68,"line_start":68},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":75,"line_start":75},{"file":"SKILL.md","line_end":76,"line_start":76},{"file":"SKILL.md","line_end":77,"line_start":77},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":107,"line_start":107},{"file":"SKILL.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":109,"line_start":109},{"file":"SKILL.md","line_end":119,"line_start":119},{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":121,"line_start":121},{"file":"SKILL.md","line_end":122,"line_start":122},{"file":"SKILL.md","line_end":123,"line_start":123},{"file":"SKILL.md","line_end":136,"line_start":127}]}],"critical_findings":[],"high_findings":[{"title":"Mutating brokerage skill labeled as read tier","locations":[{"file":"SKILL.md","line_end":14,"line_start":10},{"file":"SKILL.md","line_end":78,"line_start":70}],"confidence":0.99,"description":"Metadata sets tier to read and enables default installation, while the skill can buy, sell, cancel, replace, and schedule recurring purchases with real funds.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The metadata and command descriptions directly conflict in SKILL.md. The skill documents real account mutations that require Trade permission despite declaring a read tier."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":20,"total_lines":1328,"audit_model":"codex","audited_at":"2026-07-23T18:14:41.369+00:00","created_at":"2026-07-25T21:21:44.092858+00:00","static_findings":[{"id":"external_commands:references/assets.md:6:ruby-shell-backtick-execution","file":"references/assets.md","pattern":"Ruby/shell backtick execution","snippet":"Returns: currency, `net_assets`, `total_cash`, `buy_power`, `max_finance_amount`, `remaining_finance","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:references/assets.md:23:ruby-shell-backtick-execution","file":"references/assets.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":30,"severity":"medium","line_start":23},{"id":"external_commands:references/bank-cards.md:18:ruby-shell-backtick-execution","file":"references/bank-cards.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":25,"severity":"medium","line_start":18},{"id":"external_commands:references/cash-flow.md:6:ruby-shell-backtick-execution","file":"references/cash-flow.md","pattern":"Ruby/shell backtick execution","snippet":"Returns: `flow_name`, symbol, `business_type`, balance, currency, `business_time`, description. Defa","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:references/cash-flow.md:24:ruby-shell-backtick-execution","file":"references/cash-flow.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":31,"severity":"medium","line_start":24},{"id":"blocker:references/dca.md:9:system-reconnaissance","file":"references/dca.md","pattern":"System reconnaissance","snippet":"- If the user did not specify the **amount**, ask. Do not default.","category":"blocker","line_end":9,"severity":"low","line_start":9},{"id":"blocker:references/dca.md:10:system-reconnaissance","file":"references/dca.md","pattern":"System reconnaissance","snippet":"- If the user did not specify the **frequency** (`daily` / `weekly` / `fortnightly` / `monthly`), as","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:references/dca.md:11:system-reconnaissance","file":"references/dca.md","pattern":"System reconnaissance","snippet":"- If the user said \"weekly\" without naming a `day-of-week`, ask.","category":"blocker","line_end":11,"severity":"low","line_start":11},{"id":"blocker:references/dca.md:12:system-reconnaissance","file":"references/dca.md","pattern":"System reconnaissance","snippet":"- If the user said \"monthly\" without naming a `day-of-month`, ask.","category":"blocker","line_end":12,"severity":"low","line_start":12},{"id":"blocker:references/dca.md:13:system-reconnaissance","file":"references/dca.md","pattern":"System reconnaissance","snippet":"- If the user did not specify when to **stop** (or that the plan is open-ended), confirm explicitly.","category":"blocker","line_end":13,"severity":"low","line_start":13},{"id":"blocker:references/dca.md:22:system-reconnaissance","file":"references/dca.md","pattern":"System reconnaissance","snippet":"1. **Preview** — describe exactly what you are about to do (symbol, amount + currency, frequency, da","category":"blocker","line_end":22,"severity":"low","line_start":22},{"id":"blocker:references/dca.md:49:system-reconnaissance","file":"references/dca.md","pattern":"System reconnaissance","snippet":"If the user gives a **symbol** but no plan id for pause/resume/stop/update, first run `longbridge dc","category":"blocker","line_end":49,"severity":"low","line_start":49},{"id":"blocker:references/dca.md:85:system-reconnaissance","file":"references/dca.md","pattern":"System reconnaissance","snippet":"For pause / resume / stop / update — list plan id + symbol + amount + frequency + new state, then as","category":"blocker","line_end":85,"severity":"low","line_start":85},{"id":"external_commands:references/fund-positions.md:6:ruby-shell-backtick-execution","file":"references/fund-positions.md","pattern":"Ruby/shell backtick execution","snippet":"Returns: symbol, name, `current_net_asset_value`, `cost_net_asset_value`, currency, `holding_units`.","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:references/fund-positions.md:18:ruby-shell-backtick-execution","file":"references/fund-positions.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":25,"severity":"medium","line_start":18},{"id":"external_commands:references/margin-ratio.md:6:ruby-shell-backtick-execution","file":"references/margin-ratio.md","pattern":"Ruby/shell backtick execution","snippet":"Returns: `im_factor` (initial), `mm_factor` (maintenance), `fm_factor` (forced liquidation). Example","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:references/margin-ratio.md:22:ruby-shell-backtick-execution","file":"references/margin-ratio.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":29,"severity":"medium","line_start":22},{"id":"external_commands:references/max-qty.md:6:ruby-shell-backtick-execution","file":"references/max-qty.md","pattern":"Ruby/shell backtick execution","snippet":"Returns: `cash_max_qty` (cash only), `margin_max_qty` (with margin financing). Example: longbridge m","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:references/max-qty.md:33:ruby-shell-backtick-execution","file":"references/max-qty.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":40,"severity":"medium","line_start":33},{"id":"external_commands:references/order.md:39:ruby-shell-backtick-execution","file":"references/order.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":46,"severity":"medium","line_start":39},{"id":"blocker:references/performance-attribution.md:3:system-reconnaissance","file":"references/performance-attribution.md","pattern":"System reconnaissance","snippet":"Decomposes a portfolio's return into attributable components using Brinson-Hood-Beebower sector attr","category":"blocker","line_end":3,"severity":"low","line_start":3},{"id":"external_commands:references/portfolio.md:8:ruby-shell-backtick-execution","file":"references/portfolio.md","pattern":"Ruby/shell backtick execution","snippet":"Returns: overview (`total_asset`, `market_cap`, `total_cash`, `total_pl`, `total_today_pl`, `margin_","category":"external_commands","line_end":8,"severity":"medium","line_start":8},{"id":"external_commands:references/portfolio.md:26:ruby-shell-backtick-execution","file":"references/portfolio.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":33,"severity":"medium","line_start":26},{"id":"external_commands:references/positions.md:6:ruby-shell-backtick-execution","file":"references/positions.md","pattern":"Ruby/shell backtick execution","snippet":"Returns: symbol, name, quantity, `available_quantity`, `cost_price`, currency, market. Example: long","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:references/positions.md:18:ruby-shell-backtick-execution","file":"references/positions.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":25,"severity":"medium","line_start":18},{"id":"blocker:references/profit-analysis.md:68:system-reconnaissance","file":"references/profit-analysis.md","pattern":"System reconnaissance","snippet":"| Invalid date range               | 日期格式须为 YYYY-MM-DD,开始日期须早于结束日期   | 日期格式須為 YYYY-MM-DD,開始日期須早於結束日期","category":"blocker","line_end":68,"severity":"low","line_start":68},{"id":"external_commands:references/statement.md:6:ruby-shell-backtick-execution","file":"references/statement.md","pattern":"Ruby/shell backtick execution","snippet":"Without a subcommand, lists available statements (equivalent to `statement list`). Example: longbrid","category":"external_commands","line_end":6,"severity":"medium","line_start":6},{"id":"external_commands:references/statement.md:34:ruby-shell-backtick-execution","file":"references/statement.md","pattern":"Ruby/shell backtick execution","snippet":"Print verbose request info (host, elapsed) to stderr, prefixed with `*` like curl -v","category":"external_commands","line_end":41,"severity":"medium","line_start":34},{"id":"blocker:references/tax-harvesting.md:45:system-reconnaissance","file":"references/tax-harvesting.md","pattern":"System reconnaissance","snippet":"When suggesting substitutes to avoid wash-sale, recommend securities that are economically similar b","category":"blocker","line_end":45,"severity":"low","line_start":45},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Run `longbridge <cmd> --help` for current flags and output fields.","category":"external_commands","line_end":56,"severity":"medium","line_start":56},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `assets` — account net assets, cash, buying power, margin breakdown","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `cash-flow` — cash flow records (deposits, withdrawals, dividends)","category":"external_commands","line_end":59,"severity":"medium","line_start":59},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `portfolio` — total assets, P&L, holdings, intraday P&L","category":"external_commands","line_end":60,"severity":"medium","line_start":60},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `positions` — current stock positions across all sub-accounts 🔐","category":"external_commands","line_end":61,"severity":"medium","line_start":61},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `fund-positions` — current fund positions across all sub-accounts 🔐","category":"external_commands","line_end":62,"severity":"medium","line_start":62},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `margin-ratio` — margin ratio requirements for a symbol","category":"external_commands","line_end":63,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `max-qty` — estimated max buy or sell quantity","category":"external_commands","line_end":64,"severity":"medium","line_start":64},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `profit-analysis` — profit and loss analysis","category":"external_commands","line_end":65,"severity":"medium","line_start":65},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `statement` — download and export account statements (daily/monthly)","category":"external_commands","line_end":66,"severity":"medium","line_start":66},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `bank-cards` — list bank cards for the current account","category":"external_commands","line_end":67,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `withdrawals` — withdrawal history 🔐","category":"external_commands","line_end":68,"severity":"medium","line_start":68},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `deposits` — deposit history 🔐","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `order` — list, detail, buy, sell, cancel, replace orders 🔐 ⚠️ mutating","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"### `dca` — recurring investment: list, create, pause, resume, cancel 🔐 ⚠️ mutating","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `margin-ratio`, `max-qty`: Public — no login required","category":"external_commands","line_end":75,"severity":"medium","line_start":75},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `assets`, `cash-flow`, `portfolio`, `profit-analysis`: 🔐 Requires Quote permission","category":"external_commands","line_end":76,"severity":"medium","line_start":76},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `positions`, `fund-positions`, `statement`, `bank-cards`, `withdrawals`, `deposits`: 🔐 Requires T","category":"external_commands","line_end":77,"severity":"medium","line_start":77},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `order`, `dca` (mutating operations): 🔐 Requires Trade permission — **always present a preview be","category":"external_commands","line_end":78,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `command not found: longbridge` | Install longbridge-terminal |","category":"external_commands","line_end":107,"severity":"medium","line_start":107},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `not logged in` / `unauthorized` | Run `longbridge auth login`; tick Trade permission |","category":"external_commands","line_end":108,"severity":"medium","line_start":108},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `order` / `dca` mutation | Always preview plan first; wait for user confirmation before executing ","category":"external_commands","line_end":109,"severity":"medium","line_start":109},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Real-time market quotes | `longbridge-market-data` |","category":"external_commands","line_end":119,"severity":"medium","line_start":119},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Fundamental analysis | `longbridge-fundamentals` |","category":"external_commands","line_end":120,"severity":"medium","line_start":120},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Watchlist management | `longbridge-watchlist` |","category":"external_commands","line_end":121,"severity":"medium","line_start":121},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Institutional** shareholders / fund holders (not my account) | `longbridge-research` |","category":"external_commands","line_end":122,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| IPO subscription orders | `longbridge-market-data` (ipo command) |","category":"external_commands","line_end":123,"severity":"medium","line_start":123},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":136,"severity":"medium","line_start":127}],"finding_verdicts":[{"id":"external_commands:references/assets.md:6:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for CLI fields or examples in prose. No Ruby code, shell substitution, or executable script appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/assets.md:23:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/bank-cards.md:18:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/cash-flow.md:6:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for CLI fields or examples in prose. No Ruby code, shell substitution, or executable script appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/cash-flow.md:24:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dca.md:9:system-reconnaissance","reason":"This line asks the user to supply a missing investment amount before creating a plan. It does not inspect the host system or collect system details.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dca.md:10:system-reconnaissance","reason":"This line asks the user to choose a recurring-investment frequency. It is transaction clarification, not system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dca.md:11:system-reconnaissance","reason":"This line requests a missing day of week for a weekly plan. It does not query or enumerate the host environment.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dca.md:12:system-reconnaissance","reason":"This line requests a missing day of month for a monthly plan. It contains no host or network discovery.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dca.md:13:system-reconnaissance","reason":"This line requires confirmation of a DCA plan end condition. It is a financial safeguard, not system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dca.md:22:system-reconnaissance","reason":"This line requires a complete preview before a financial mutation. It describes user-facing transaction details and does not inspect the system.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dca.md:49:system-reconnaissance","reason":"This line looks up a user-authorized DCA plan identifier through the Longbridge CLI. It does not gather host, process, or network configuration.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dca.md:85:system-reconnaissance","reason":"This line defines a confirmation preview for changing a DCA plan. It contains no operating-system discovery behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/fund-positions.md:6:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for CLI fields or examples in prose. No Ruby code, shell substitution, or executable script appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/fund-positions.md:18:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/margin-ratio.md:6:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for CLI fields or examples in prose. No Ruby code, shell substitution, or executable script appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/margin-ratio.md:22:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/max-qty.md:6:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for CLI fields or examples in prose. No Ruby code, shell substitution, or executable script appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/max-qty.md:33:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/order.md:39:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/performance-attribution.md:3:system-reconnaissance","reason":"This line describes portfolio return attribution methodology. It does not request or inspect any system information.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/portfolio.md:8:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for CLI fields or examples in prose. No Ruby code, shell substitution, or executable script appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/portfolio.md:26:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/positions.md:6:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for CLI fields or examples in prose. No Ruby code, shell substitution, or executable script appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/positions.md:18:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/profit-analysis.md:68:system-reconnaissance","reason":"This line is a multilingual validation message for an invalid date range. It has no reconnaissance behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/statement.md:6:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for CLI fields or examples in prose. No Ruby code, shell substitution, or executable script appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:references/statement.md:34:ruby-shell-backtick-execution","reason":"The backticks format the literal asterisk in copied CLI help text. This location contains documentation only, with no Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/tax-harvesting.md:45:system-reconnaissance","reason":"This line constrains substitute-security recommendations for wash-sale analysis. It does not inspect the local system.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:56:ruby-shell-backtick-execution","reason":"The backticks are Markdown delimiters around a documented Longbridge help command. There is no Ruby code or shell command-substitution syntax at this line.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:59:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:60:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:61:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:62:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:64:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:65:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:66:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:68:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:75:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:76:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:77:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:107:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:108:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:109:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:119:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:120:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:121:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:123:ruby-shell-backtick-execution","reason":"The backticks provide Markdown formatting for command, permission, error, or related-skill names. No executable Ruby or shell construct appears at this location.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The backticks open a Markdown code fence that documents the file layout. They do not invoke Ruby, a shell, or command substitution.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[{"title":"Mutating brokerage skill labeled as read tier","severity":"high","locations":[{"file":"SKILL.md","line_end":14,"line_start":10},{"file":"SKILL.md","line_end":78,"line_start":70}],"confidence":0.99,"description":"Metadata sets tier to read and enables default installation, while the skill can buy, sell, cancel, replace, and schedule recurring purchases with real funds.","confidence_reasoning":"The metadata and command descriptions directly conflict in SKILL.md. The skill documents real account mutations that require Trade permission despite declaring a read tier."}],"subject_marketplace_commit_sha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","subject_content_hash":"b3e3beeaf9a0499fd000d7a857d13f83e3dbc779f46a21673690f64b020745ec","subject_tree_hash":"eee64b7768ebdfeece30f6485753a4eb8ee761a4b4888ef882f07f56161bc00f","subject_plugin_path":"skills/longbridge/longbridge-portfolio","audit_payload_hash":"4475bccb652774177eda8d29ce48b5b9","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006","contentHash":"b3e3beeaf9a0499fd000d7a857d13f83e3dbc779f46a21673690f64b020745ec","treeHash":"eee64b7768ebdfeece30f6485753a4eb8ee761a4b4888ef882f07f56161bc00f","pluginPath":"skills/longbridge/longbridge-portfolio","auditPayloadHash":"4475bccb652774177eda8d29ce48b5b9"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/longbridge-longbridge-portfolio/audits/5/attestation","status":"superseded"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"superseded","verificationState":"not_verified"},"isLatest":false}}