Audit History
longbridge-portfolio - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Aug 8, 2026, 09:47 AM | 3 confirmed | 0 | No capability change |
| v5 | Jul 23, 2026, 06:14 PM | 1 confirmed | 0 | No capability change |
| v4 | Jul 8, 2026, 05:07 AM | 2 confirmed | 0 | No capability change |
| v3 | Jul 5, 2026, 09:04 PM | 2 confirmed | 0 | Network access |
| v2 | Jun 30, 2026, 08:12 AM | 2 confirmed | 0 | No capability change |
| v1 | Jun 8, 2026, 11:09 AM | No confirmed findings | 0 | Baseline |
Aug 8, 2026, 09:47 AM
All 58 static alerts are false positives caused by Markdown formatting or ordinary financial guidance; no Ruby backtick execution, system reconnaissance, or prompt injection was found. The skill still has high-impact capabilities because it can access private brokerage data and execute real-money account changes through the Longbridge CLI or discovered MCP tools.
Confirmed security concerns (3)
Risk Factors
βοΈ External commands (47)
Jul 23, 2026, 06:14 PM
All 57 static alerts are false positives caused by Markdown backticks or ordinary clarification text; the cited lines contain no Ruby execution, shell substitution, or system reconnaissance. However, SKILL.md declares a read tier and default installation while exposing real-money order and DCA mutations. Publication should require corrected metadata and clear installation warnings for Trade permission and financial side effects.
Confirmed security concerns (1)
Risk Factors
βοΈ External commands (46)
Jul 8, 2026, 05:07 AM
No evidence of Ruby backtick execution or prompt injection was found; the static backtick hits are Markdown code spans, headings, or copied CLI help text. The skill still has high semantic risk because it guides Longbridge brokerage data access and real-money order or DCA operations with explicit confirmation safeguards.
Confirmed security concerns (2)
Risk Factors
βοΈ External commands (46)
Jul 5, 2026, 09:04 PM
All static backtick and system reconnaissance alerts were reviewed against Markdown context and judged false positives. The backtick alerts are inline code, CLI help excerpts, or code fences, not Ruby or shell backtick execution. Two semantic risks remain: the skill can access sensitive brokerage data and can perform confirmed order or DCA mutations that affect real money.
Confirmed security concerns (2)
Risk Factors
βοΈ External commands (46)
Jun 30, 2026, 08:12 AM
Static analysis reported many backtick, weak-crypto, reconnaissance, and one URL finding, but reviewed examples are markdown documentation and finance-analysis text rather than executable code. The real risk is intentional use of Longbridge external commands that can access account data and mutate brokerage state, so publication should include a clear medium-risk warning.
Confirmed security concerns (2)
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
βοΈ External commands (5)
π Network access (1)
Detected Patterns
Jun 8, 2026, 11:09 AM
This is a prompt-only documentation skill with no executable scripts or commands. All 265 static findings are false positives: the 246 'external_commands' findings match markdown backtick formatting in documentation, the 18 'weak cryptographic algorithm' findings match text strings in reference docs, and 'system reconnaissance' findings match risk-analysis terminology. The skill instructs the LLM to call the longbridge CLI or MCP server at runtimeβit does not execute code itself.