Skills longbridge-watchlist
๐Ÿ“ฆ

longbridge-watchlist

v1.0.0 Content revision r3 Medium Risk โš™๏ธ External commands

Manage Longbridge Watchlists and Price Alerts

Managing watchlists, alerts, and public stock lists across separate commands is repetitive. This skill organizes those workflows and requires confirmation before persistent changes.

Supports: Claude Codex Code(CC)
๐Ÿ“Š 69 Adequate

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "longbridge-watchlist" from https://skillstore.io/skills/longbridge-longbridge-watchlist.md and its manifest at https://skillstore.io/api/skills/longbridge-longbridge-watchlist/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "longbridge-watchlist". Show my watchlist groups.

Expected outcome:

  • Technology | Group 12345 | AAPL.US, NVDA.US
  • Hong Kong Banks | Group 67890 | 5.HK, 11.HK

Using "longbridge-watchlist". Add NVDA.US to my Technology group.

Expected outcome:

About to add NVDA.US to Technology, group 12345. No other symbols will change. Confirm execution?

Using "longbridge-watchlist". Show popular community stock lists.

Expected outcome:

  • AI Leaders | 12 symbols | 8,240 subscribers
  • Dividend Focus | 20 symbols | 5,110 subscribers

Security Audit

Medium Risk
v6 โ€ข 8/8/2026 Open versioned report

The four reconnaissance alerts are normal preview and lookup instructions. The 12 shell-backtick alerts identify Markdown code spans, not Ruby execution. However, command templates interpolate user-provided values without explicit argument escaping, creating a medium command-injection risk.

4
Files scanned
295
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Unsafe Shell Argument Construction Guidance
Command templates place user-controlled symbols, alert IDs, prices, and group names into shell commands without requiring validation or structured argument passing.
The templates visibly interpolate user-derived placeholders into commands. A safe executor could avoid shell parsing, but the instructions do not require that protection.
Audited by: codex View Audit History โ†’
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/longbridge-longbridge-watchlist/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/longbridge-longbridge-watchlist/security.svg)](https://skillstore.io/skills/longbridge-longbridge-watchlist?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/longbridge-longbridge-watchlist?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/longbridge-longbridge-watchlist/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/longbridge-longbridge-watchlist.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

longbridge. (2026). longbridge-watchlist security audit report (audit version 6) [Author version 1.0.0]. Skillstore. https://skillstore.io/skills/longbridge-longbridge-watchlist/audits/6

BibTeX citation

@techreport{longbridge-longbridge-longbridge-watchlist-2026, author = {longbridge}, title = {longbridge-watchlist security audit report (audit version 6)}, institution = {Skillstore}, year = {2026}, number = {6}, url = {https://skillstore.io/skills/longbridge-longbridge-watchlist/audits/6}, note = {Author version 1.0.0} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "longbridge-watchlist security audit report (audit version 6)" version: "1.0.0" type: report authors: - name: "longbridge" date-released: "2026-08-08" url: "https://skillstore.io/skills/longbridge-longbridge-watchlist/audits/6" identifiers: - type: other value: "skillstore:longbridge-longbridge-watchlist:audit:6" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: High
45
Architecture
100
Maintainability
85
Content
67
Community
83
Spec Compliance

What You Can Build

Maintain Personal Watchlists

Review groups, add selected symbols, and remove outdated holdings with confirmation.

Configure Research Alerts

Create price thresholds for tracked companies and manage existing alert states.

Curate Community Lists

Browse public lists and maintain a subscribed collection of selected market symbols.

Try These Prompts

List Watchlists
List my Longbridge watchlist groups and summarize each group with its ID and symbols.
Add a Symbol Safely
Prepare to add NVDA.US to my Technology group. Show the exact change and wait for my confirmation before execution.
Configure a Price Alert
Set a falling price alert for TSLA.US at 220 USD. Preview the alert details and request confirmation before creating it.
Curate a Community List
Review sharelist 123, propose adding AAPL.US and removing TSLA.US, then execute only the changes I explicitly confirm.

Best Practices

  • Provide complete market symbols such as AAPL.US or 700.HK.
  • Review every preview and confirm only when all identifiers and values are correct.
  • Use read operations first when a group or alert ID is unknown.

Avoid

  • Do not request a mutation with an ambiguous group, symbol, price, or direction.
  • Do not bypass the confirmation step or approve changes you have not reviewed.
  • Do not expect this skill to place trades or provide investment advice.

Frequently Asked Questions

Does this skill place trades?
No. It manages watchlists, price alerts, and community stock lists.
Is a Longbridge account required?
Public community lists may be readable without login. Account-specific watchlists and changes require authentication.
Why does the skill ask for confirmation?
Changes persist in your Longbridge account. Confirmation lets you verify symbols, IDs, prices, and directions before execution.
Which symbol format should I use?
Use the market-qualified format, such as TSLA.US or 700.HK.
Can it manage price alert directions?
Yes. Specify whether the alert triggers when price rises above or falls below the target.
What happens when a command fails?
The skill reports the error and does not silently retry a mutating operation.

Developer Details

Author

longbridge

License

MIT

Author version

v1.0.0

Skillstore revision

r3

Version notice

The installable content changed, but the author did not update the declared version.

Ref

656be3040aef5c047555a908cd5c695d22a4a548

Maintenance freshness

8/8/2026

Usage

5 downloads ยท 0 views

File structure

๐Ÿ“ references/

๐Ÿ“„ alert.md

๐Ÿ“„ sharelist.md

๐Ÿ“„ watchlist.md

๐Ÿ“„ SKILL.md

More from longbridge

View all
View all