Audit History
longbridge-market-data - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Aug 8, 2026, 09:43 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 23, 2026, 06:09 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 05:02 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 06:37 PM | 2 confirmed | 0 | Network access |
| v2 | Jun 30, 2026, 08:10 AM | No confirmed findings | 1 | No capability change |
| v1 | Jun 8, 2026, 11:07 AM | No confirmed findings | 0 | Baseline |
Aug 8, 2026, 09:43 AM
All 55 static findings are false positives caused by Markdown backticks, command documentation, or market-domain terms. No executable Ruby code, system reconnaissance, prompt injection, or malicious intent was found.
Risk Factors
⚙️ External commands (46)
Jul 23, 2026, 06:09 PM
All 54 static alerts are false positives caused by Markdown code spans, fenced examples, or finance-domain terms. The skill uses a fixed Longbridge CLI or MCP for its stated purpose; no dynamic shell construction, prompt injection, exfiltration, or system reconnaissance was found. Account-specific IPO and subscription features still require the permissions documented by the skill.
Risk Factors
⚙️ External commands (45)
Jul 8, 2026, 05:02 AM
All static findings are false positives caused by Markdown backticks, CLI help excerpts, usage examples, or market-data terminology. No evidence found of prompt injection, covert exfiltration, malicious command execution, or system reconnaissance intent in the reviewed files.
Risk Factors
⚙️ External commands (45)
Jul 6, 2026, 06:37 PM
Most static findings are false positives from Markdown backticks and CLI documentation, not executable Ruby or shell backtick code. No prompt injection text was found. Two semantic issues remain: account-specific IPO data appears in a market-data skill, and some guidance relays stderr verbatim.
Confirmed security concerns (2)
Risk Factors
⚙️ External commands (45)
Jun 30, 2026, 08:10 AM
This is a prompt-only Markdown skill that documents Longbridge CLI workflows for market data. The static external-command and weak-crypto alerts are false positives caused by Markdown code formatting, command examples, formulas, and market terminology. No malicious intent, prompt injection, scripts, or data exfiltration paths were found, but local CLI and network-backed data access remain disclosed risk factors.
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (3)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (4)
🌐 Network access (1)
Jun 8, 2026, 11:07 AM
The skill is a prompt-only markdown documentation set (19 files, 995 lines) that instructs the LLM to invoke the Longbridge CLI for market data. All 331 'external_commands' and 37 'weak cryptographic algorithm' static findings are false positives: backticks in markdown are code formatting (e.g. `longbridge quote`), and hash references are documentation context, not executable code. The one 'hardcoded URL' is a legitimate GitHub project link. No scripts, no code execution, no data exfiltration paths.
Static false positives ignored (2)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.