Audit History
longbridge-value-investing - 6 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v6 Latest | Aug 8, 2026, 10:07 AM | No confirmed findings | 0 | No capability change |
| v5 | Jul 23, 2026, 06:31 PM | No confirmed findings | 0 | No capability change |
| v4 | Jul 8, 2026, 05:28 AM | No confirmed findings | 0 | No capability change |
| v3 | Jul 5, 2026, 09:29 PM | No confirmed findings | 0 | Network access |
| v2 | Jun 30, 2026, 08:25 AM | 1 confirmed | 1 | Network access |
| v1 | Jun 8, 2026, 11:17 AM | 2 confirmed | 1 | Baseline |
Aug 8, 2026, 10:07 AM
All nine static findings are false positives caused by ordinary financial prose, inline Markdown code, or a fenced file tree. No prompt injection, data-exfiltration intent, or other net-new semantic security issue was found.
Risk Factors
βοΈ External commands (7)
Jul 23, 2026, 06:31 PM
All eight static findings are false positives caused by Markdown text, related-skill identifiers, or a fenced directory tree. No malicious command execution, system reconnaissance, prompt injection, or other semantic security issue was found.
Risk Factors
βοΈ External commands (6)
Jul 8, 2026, 05:28 AM
All eight static findings were adjudicated as false positives. The flagged lines are markdown documentation for financial-analysis rules, related skill names, or file layout, and no prompt-injection language was found.
Risk Factors
βοΈ External commands (6)
Jul 5, 2026, 09:29 PM
The static findings are false positives caused by Markdown formatting, finance notation, and file-layout documentation. I found no prompt injection text or malicious intent in the reviewed skill files; the skill is a prompt-only research workflow that uses Longbridge data and source-tagging rules.
Risk Factors
βοΈ External commands (6)
Jun 30, 2026, 08:25 AM
Static analysis reported many external-command and weak-crypto patterns. Manual review found no prompt-injection attempt or malicious code; weak-crypto hits are false positives, while Longbridge CLI execution and WebSearch fallback are intentional workflow features. Publish with a medium-risk warning because user-influenced market symbols are passed to local CLI commands and live searches.
Confirmed security concerns (1)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Static false positives ignored (1)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
βοΈ External commands (5)
Detected Patterns
Jun 8, 2026, 11:17 AM
All 176 static findings are false positives. This is a prompt-only markdown documentation skill with no executable code. The 'Ruby/shell backtick execution' findings (158 instances) are triggered by backtick characters in markdown code blocks containing CLI command examples (e.g. `longbridge quote <SYMBOL> --format json`), not actual code execution. The 'Weak cryptographic algorithm' findings (18 instances) are false matches on text patterns in documentation. The 'System reconnaissance' findings match on financial sector terms (banks/insurance/REITs), not system commands.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.