Back to skill

Security audit

longbridge-trader

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Longbridge trading skill, but it gives an agent live brokerage access with broad auto-triggering and incomplete safeguards for financial actions.

Install only if you intend to let Codex access a Longbridge brokerage account. Use isolated, least-privilege credentials, prefer read-only or sandbox credentials where possible, pin and verify the longport SDK before use, and require explicit confirmation for every state-changing action including order cancellation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party Trading SDK Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:12
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- Python package: `longport` (installed via `pip install longport`)

Technical Analysis

The installation instruction resolves and installs the latest available package named longport without an exact version constraint, package hash, lockfile, or verified source declaration. This makes the executed dependency mutable after the Skill has been reviewed.

The package operates in a sensitive context: the documented workflow initializes the SDK using Config.from_env(), which reads Longbridge application credentials and an access token. The SDK is then authorized to query account data and perform live brokerage operations. Consequently, a compromised or unexpectedly modified dependency version would execute with access to those credentials and capabilities.

This finding concerns unsafe dependency pinning and verification. The audited files do not establish that the current longport package is malicious.

Attack Path

  1. An attacker compromises the dependency publisher, package-distribution account, or relevant package infrastructure.
  2. The attacker publishes a malicious or backdoored release under the expected package name.
  3. A user follows the documented pip install longport instruction.
  4. Package resolution installs the attacker-controlled release because no reviewed version or hash is enforced.
  5. The package is imported and initialized through Config.from_env().
  6. Malicious package code accesses the Longbridge environment credentials or abuses the authenticated SDK context.
  7. Depending on the account's API permissions, the attacker can expose account information or initiate unauthorized brokerage activity.

Impact Assessment

Successful exploitation could expose LONGPORT_APP_KEY, LONGPORT_APP_SECRET, and `LONG ...[truncated 486 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the SDK to an exact, reviewed version, for example through a requirements file using longport==<reviewed-version>.
  2. Require package hashes with pip install --require-hashes or an equivalent reproducible dependency-management mechanism.
  3. Document the verified official package source and publisher identity.
  4. Use a lockfile and a controlled dependency-update process that includes review and security testing before version changes.
  5. Install the SDK in an isolated virtual environment or container with minimal filesystem and network privileges.
  6. Configure Longbridge credentials according to least privilege, separating read-only market or account access from live trading access where supported.
  7. Rotate credentials promptly if dependency compromise is suspected, and monitor brokerage audit logs for unauthorized activity.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:52
Finding

Order Cancellation Is Not Protected by Explicit User Confirmation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:52-59 and SKILL.md:88-106
Vulnerability Type: Missing authorization confirmation for a financially consequential operation
Risk Level: Medium

Vulnerable Code Snippet:

markdown
## Safety Rules

**Order submission and modification must follow this process:**

1. First show the user the complete order parameters (symbol, direction, type, quantity, and price)
2. Explicitly ask the user "Confirm placing the order?"
3. Execute only after receiving user confirmation

**Forbidden**: Execute any buy/sell/modify operation without explicit user confirmation. Query operations (quotes, positions, and balances) do not require confirmation and may be executed directly.
python
# Cancel order
ctx.cancel_order(order_id="xxx")

Technical Analysis

The Skill establishes a confirmation boundary for order submission and modification, but it does not apply that boundary to order cancellation. The trading workflow nevertheless exposes ctx.cancel_order() as an executable operation.

Cancellation is a state-changing brokerage action rather than a read-only query. Canceling an order can remove an intended entry, exit, hedge, stop, or other protective instruction. Because the safety rules do not require the Agent to retrieve the current order, display its details, and obtain final confirmation, an ambiguous request or incorrect order identifier can lead directly to a consequential account change.

The issue is a missing confirmation and validation control. The audited documentation does not itself demonstrate that an unauthorized cancellation has occurred.

Attack Path

  1. A user request is ambiguous, contains an incorrect order identifier, or is interpreted by the Agent as a cancellation request.
  2. The Agent follows the documented cancellation example.
  3. Because the safety policy only explicitly protects submission and modification, the Agent do ...[truncated 849 chars]
Remediation
View remediation

Remediation Suggestions

  1. Extend the explicit-confirmation policy to every state-changing trading operation, including cancellation.
  2. Before cancellation, retrieve the target order and show its order ID, symbol, side, type, quantity, price, fill status, and current status.
  3. Ask an unambiguous confirmation question that identifies the exact order, such as: “Confirm cancellation of order <order-id> for <symbol>?”
  4. Execute cancellation only after a fresh, explicit affirmative response from the user.
  5. Reject ambiguous confirmations and require clarification when multiple orders could match the request.
  6. Revalidate the order immediately before cancellation to detect stale state, partial fills, replacement, or an already completed cancellation.
  7. Report the broker response and resulting order status after execution.
  8. Apply the same confirmation framework consistently to submission, replacement, cancellation, and any future state-changing brokerage methods.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill declaration says it 'must' trigger for a very wide range of ordinary finance-related mentions, including casual questions like stock prices or account money. In a trading skill with read/write brokerage capabilities, over-broad activation can route benign conversation into a privileged context, increasing the chance of unintended account access, exposure of sensitive financial data, or escalation toward trading actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill exposes highly sensitive financial information including balances, positions, orders, executions, and cash flows, but the description does not warn that these are confidential account data. In this context, lack of an explicit privacy warning and handling guidance makes inadvertent disclosure more likely, especially because the skill is designed to auto-trigger broadly and query operations do not require confirmation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes the skill as helping users query quotes/K-lines/depth and perform trading/account operations such as placing, modifying, canceling orders, checking balances, and holdings. Lines L219-L226 add self-selected watchlist creation, update, and deletion features, which are not mentioned in that stated scope and represent portfolio-list management behavior beyond the described functions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This documentation exposes direct order submission, cancellation, and modification primitives for a live trading skill without any explicit user-safety guidance, confirmation requirements, or indication that the actions affect real brokerage accounts. In the context of an agent skill that must trigger on casual trading-related queries, this increases the chance of unintended destructive financial actions if the skill is invoked too broadly or implemented without additional safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file presents all headings, descriptions, and field explanations in Chinese only, which can amount to a language/locale policy issue if users are not given an opt-in choice. The file does not indicate that the skill is region-specific or provide an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file is entirely presented in Chinese and does not offer an alternative language or indicate that the locale restriction is intentional or region-specific. Under the policy rule, forcing a specific language without user opt-in can be considered a locale/language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The example loads configuration from environment variables without warning that the environment may contain sensitive brokerage credentials, tokens, or account identifiers. In a trading skill context, mishandling these secrets could expose account access or enable unauthorized trading if logs, debug output, or shared execution environments leak them.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.