Versioned security assessment

Report ID: SA-EBDFE608

7/23/2026, 6:04:31 PM

longbridge-intel security assessment v5

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Historical report
Skill name
longbridge-intel
Version
v1.0.0
Maintainer
longbridge
Coverage
18 Files scanned · 1,433 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

High

1 confirmed security finding requires attention.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

All 26 static detections are false positives caused by Markdown formatting or financial terminology. No Ruby or shell backtick execution appears at the cited lines. The catalyst workflow requests private positions and account changes despite read-only, no-login metadata.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Attestation superseded

A newer attestation exists.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

18 Files scanned · 1,433 Lines analyzed

1 item shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Not recorded by this audit

Filesystem access

May read or write local files.

Not recorded by this audit

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 22 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (1)

RISK-001 High
Undeclared Account Data Access and State Changes
The catalyst workflow reads positions and watchlists, changes watchlist membership, and updates preferences. These actions conflict with read-only, no-login metadata.
The metadata explicitly declares read-only, no-login behavior, while the catalyst reference explicitly requests private positions and account changes.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    Undeclared account access and state changes in the catalyst workflow
    Remove account mutations, or declare authentication and write permissions. Require explicit confirmation before each change and make position access optional.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006
Content hash
833fa1e969152b0dc3a2a77525de68402e1f0d7a36e9ad7add93c1ca0b2148e8
Tree hash
bd90defface343227ef8f68fb8c32b806b2076dc3a56676e2e1cf745acd183f7
Skill path
skills/longbridge/longbridge-intel
Audit payload hash
3028da312189871557da696877c1ba94

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: superseded