Skills longbridge-earnings
๐Ÿ“ฆ

longbridge-earnings

Content revision r2 High Risk โš™๏ธ External commands๐Ÿ“ Filesystem access๐ŸŒ Network access

Analyze Earnings Before and After Results

Earnings data is fragmented across statements, estimates, calls, and market feeds. This skill organizes those inputs into timely previews, summaries, and valuation reports.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "longbridge-earnings" from https://skillstore.io/skills/longbridge-longbridge-earnings.md and its manifest at https://skillstore.io/api/skills/longbridge-longbridge-earnings/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "longbridge-earnings". Summarize the latest earnings for 700.HK.

Expected outcome:

  • Revenue beat consensus while net margin improved from the prior year.
  • Gaming and advertising led growth, while fintech remained stable.
  • Next-quarter expectations imply slower growth, with regulation and spending as key risks.

Using "longbridge-earnings". Prepare a pre-earnings preview for TSLA.US.

Expected outcome:

  • Prior delivery guidance remains the main performance benchmark.
  • Consensus and management assumptions diverge most on automotive margins.
  • Watch pricing, factory utilization, energy growth, and updated capital spending.

Using "longbridge-earnings". Create a full earnings report for a global retailer.

Expected outcome:

The report presents KPI variances, estimate revisions, three valuation scenarios, a weighted target price, rating rationale, risks, and dated source links.

Security Audit

High Risk
v8 โ€ข 8/8/2026 Open versioned report

Most static findings are Markdown formatting, ordinary financial prose, or safe argument-array subprocess use. Confirmed risks include unquoted symbol placeholders, a predictable user-derived temporary path, stale cached responses, and an external MCP trust boundary; no prompt injection or credential-exfiltration intent was found.

6
Files scanned
959
Lines analyzed
7
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Unvalidated Symbol Controls Output Path
The command-line symbol is inserted into a temporary directory name after only replacing periods. Slash and parent-directory segments can redirect fixed JSON and error files outside the intended directory.
The data flow from sys.argv to the Path expression is direct, and no allowlist or path containment check is present.
High
Failed Refresh Can Reuse Stale Financial Data
A failed fetch writes an error file but leaves any older JSON file intact. The reporting path prefers JSON over errors, so a new analysis can silently use stale results.
The output directory is stable per symbol, failure does not remove prior JSON, and section reads JSON before checking the current error file.
Capability review items (7)

These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.

Medium
Ruby/shell backtick execution
python3 scripts/collect.py <SYMBOL> --full # `python` on Windows
The executable shell example places the user-selected SYMBOL into a command without quoting. Shell metacharacters in the substituted value could execute additional commands.
Medium
Temp directory access
(`longbridge <cmd> > /tmp/data.json`), then read it โ€” the CLI may append version-notification
The workflow redirects output to the fixed shared path /tmp/data.json. A local attacker could pre-create that path or a symlink and cause clobbering under the agent's privileges.
Medium
Ruby/shell backtick execution
1. Reuse the `RAW_DIR` from a previous lite run if present; otherwise `python3 scripts/collect.py <S
The instruction places a user-selected SYMBOL directly into a shell command template without quoting. A substituted value containing shell syntax could execute unintended commands.
Medium
Ruby/shell backtick execution
- **Partial N/A sections**: the digest marks failed sources as `N/A (reason)`. Work with what succee
The fallback shows a direct shell template with cmd and SYMBOL placeholders and no quoting or allowlist. Unsafe substituted values could alter arguments or execute shell syntax.
Medium
Ruby/shell backtick execution
- **Digging into raw JSON** (full mode): read from a file, not inline JSON on a command line โ€” e.g.
The example embeds RAW_DIR inside Python source passed through a shell command. An untrusted path containing quotes or shell expansions could modify the Python expression or the surrounding command.
Low
Temp file creation
out_dir = Path(tempfile.gettempdir()) / f"lb_earnings_{symbol.lower().replace('.', '_')}"
The output directory is predictable and incorporates an unvalidated user-supplied symbol. This enables path manipulation and exposes fixed output names to local symlink or stale-file attacks.
Low
Hardcoded URL
- **No `longbridge` CLI**: if the user has run `claude mcp add --transport http longbridge https://m
The fallback introduces a remote MCP endpoint and instructs the agent to discover and use its tools. This expands the trust boundary and may transmit user queries to an external service.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/longbridge-longbridge-earnings/audits/8?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/longbridge-longbridge-earnings/security.svg)](https://skillstore.io/skills/longbridge-longbridge-earnings?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/longbridge-longbridge-earnings?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/longbridge-longbridge-earnings/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/longbridge-longbridge-earnings.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

longbridge. (2026). longbridge-earnings security audit report (audit version 8) [Author version unspecified]. Skillstore. https://skillstore.io/skills/longbridge-longbridge-earnings/audits/8

BibTeX citation

@techreport{longbridge-longbridge-longbridge-earnings-2026, author = {longbridge}, title = {longbridge-earnings security audit report (audit version 8)}, institution = {Skillstore}, year = {2026}, number = {8}, url = {https://skillstore.io/skills/longbridge-longbridge-earnings/audits/8}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "longbridge-earnings security audit report (audit version 8)" version: "unspecified" type: report authors: - name: "longbridge" date-released: "2026-08-08" url: "https://skillstore.io/skills/longbridge-longbridge-earnings/audits/8" identifiers: - type: other value: "skillstore:longbridge-longbridge-earnings:audit:8" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: High
68
Architecture
85
Maintainability
87
Content
71
Community
83
Spec Compliance

What You Can Build

Prepare for an Upcoming Release

Review prior guidance, recent events, consensus gaps, management credibility, and key questions before results.

Summarize Reported Results

Turn quarterly data into a concise beat-or-miss card with segment, margin, outlook, and risk analysis.

Update a Valuation View

Create a sourced research report with revised estimates, scenario valuation, target price, and rating rationale.

Try These Prompts

Quick Earnings Summary
Summarize the latest reported earnings for [SYMBOL]. Show major beats or misses, guidance changes, segment trends, and key risks.
Upcoming Earnings Preview
Prepare a pre-earnings preview for [SYMBOL]. Compare prior guidance with actual performance and identify three to five questions for this release.
Detailed Results Review
Analyze [SYMBOL] for [QUARTER]. Explain KPI surprises, margin drivers, segment performance, management guidance, estimate revisions, thesis changes, and market expectations.
Full Valuation Report
Create a full Markdown earnings report for [SYMBOL]. Include sourced estimates, DCF, peer multiples, relevant transactions, scenarios, target price, rating, and risks.

Best Practices

  • Specify the ticker, exchange, reporting quarter, and whether results are upcoming or released.
  • Verify every source covers the same fiscal period before comparing results or estimates.
  • Treat ratings and target prices as research inputs, then apply independent judgment.

Avoid

  • Do not request precise conclusions when the ticker or reporting period is ambiguous.
  • Do not treat current consensus as the historical estimate baseline without checking its date.
  • Do not use generated ratings or price targets as automatic trading instructions.

Frequently Asked Questions

Which markets does this skill cover?
It supports United States, Hong Kong, and mainland China shares when Longbridge data is available.
Can it analyze results before they are released?
Yes. Pre-earnings mode reviews prior guidance, recent events, consensus gaps, call themes, and key questions.
What is the default post-earnings output?
The default is a concise in-chat card covering KPIs, segments, trends, thesis status, expectations, and risks.
Can it create a full research report?
Yes. An explicit request produces a Markdown report with detailed analysis, valuation scenarios, target price, rating, and sources.
Does it require Longbridge access?
Longbridge CLI or MCP access provides the intended data. Public web search can supplement missing transcripts and selected market context.
Does the output constitute investment advice?
No. The output supports research and may contain errors or uncertain assumptions. Verify source data and use independent judgment.

Developer Details

Author

longbridge

License

MIT

Skillstore revision

r2

Version notice

The author did not declare a version.

Ref

656be3040aef5c047555a908cd5c695d22a4a548

Maintenance freshness

8/8/2026

Usage

12 downloads ยท 2 views

File structure

๐Ÿ“ commands/

๐Ÿ“„ earnings.md

๐Ÿ“ references/

๐Ÿ“„ full-report.md

๐Ÿ“„ pre-earnings.md

๐Ÿ“„ valuation-methodologies.md

๐Ÿ“ scripts/

๐Ÿ“„ collect.py

๐Ÿ“„ SKILL.md

More from longbridge

View all
View all