Versioned security assessment

Report ID: SA-EBDFE608

7/23/2026, 6:14:41 PM

longbridge-portfolio security assessment v5

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Historical report
Skill name
longbridge-portfolio
Version
v1.0.0
Maintainer
longbridge
Coverage
20 Files scanned Β· 1,328 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

High

1 confirmed security finding requires attention.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

All 57 static alerts are false positives caused by Markdown backticks or ordinary clarification text; the cited lines contain no Ruby execution, shell substitution, or system reconnaissance. However, SKILL.md declares a read tier and default installation while exposing real-money order and DCA mutations. Publication should require corrected metadata and clear installation warnings for Trade permission and financial side effects.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Attestation superseded

A newer attestation exists.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

20 Files scanned Β· 1,328 Lines analyzed

1 item shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Not recorded by this audit

Filesystem access

May read or write local files.

Not recorded by this audit

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 46 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (1)

RISK-001 High
Mutating brokerage skill labeled as read tier
Metadata sets tier to read and enables default installation, while the skill can buy, sell, cancel, replace, and schedule recurring purchases with real funds.
The metadata and command descriptions directly conflict in SKILL.md. The skill documents real account mutations that require Trade permission despite declaring a read tier.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    The read-tier and default-install metadata conflicts with real-money mutation capabilities.
    Set the tier to the appropriate mutating classification and disable default installation for a skill that can place or alter brokerage orders.
  2. FIX-002
    Medium
    Order mutations have a shorter confirmation policy than recurring-investment mutations.
    Require a separate preview turn with symbol, side, quantity, price, and order identifier before every buy, sell, cancel, or replace action.
  3. FIX-003
    Medium
    Trade permission exposes sensitive account data and enables financial mutations.
    Show an installation disclosure listing accessed account data, required permissions, and the real-money effects of order and DCA commands.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006
Content hash
b3e3beeaf9a0499fd000d7a857d13f83e3dbc779f46a21673690f64b020745ec
Tree hash
eee64b7768ebdfeece30f6485753a4eb8ee761a4b4888ef882f07f56161bc00f
Skill path
skills/longbridge/longbridge-portfolio
Audit payload hash
4475bccb652774177eda8d29ce48b5b9

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: superseded