Back to skill

Security audit

Longbridge

Security checks for vulnerabilities and agentic risk

Overview

This Longbridge skill is mostly coherent for market data and trading help, but it includes an unsafe remote installer pattern and broad access to sensitive financial/trading workflows.

Review this skill before installing. Prefer Homebrew or verified release artifacts over the documented curl-to-sh installer, do not approve broad OAuth scopes unless needed, and require explicit confirmation before any order placement, cancellation, watchlist change, or sensitive portfolio/account retrieval.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/setup.md:10
Finding

Unverified Remote Installer Is Piped Directly Into a Shell

Content
View full analysis

Vulnerability Details

File Location: references/setup.md, line 10
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet

bash
# Any platform
curl -sSL https://github.com/longbridge/longbridge-terminal/raw/main/install | sh

Technical Analysis

The installation command retrieves a shell script from an external URL and sends it directly to sh. The URL tracks the mutable main branch rather than an immutable release or commit. Consequently, the code executed at installation time can differ from the code that was available when this Skill was audited.

No checksum, cryptographic signature, fixed version, or review step validates the downloaded content. The use of curl -sSL also suppresses normal progress and follows redirects, while the pipeline immediately executes the resulting response. Although the URL belongs to the stated Longbridge GitHub organization, trust in the organization does not eliminate risks from repository compromise, maintainer-account compromise, malicious upstream changes, redirected responses, or distribution infrastructure compromise.

Installing the CLI is consistent with the Skill's declared functionality, but executing mutable remote content without verification exceeds the minimum mechanism necessary to perform that installation. A signed package-manager release or a separately downloaded and verified artifact would provide the required functionality with less risk.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or infrastructure involved in delivering the installer.
  2. The attacker modifies the installer on the main branch or causes the URL to return attacker-controlled shell commands.
  3. A user or AI agent follows the documented installation command.
  4. curl downloads the current response and pipes it directly to sh.
  5. The shell executes the attacker-controlled commands without local inspection or integr ...[truncated 864 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer the documented Homebrew installation path or another package manager that supports signed, versioned releases.
  2. Do not pipe network responses directly into a shell.
  3. Pin downloads to an immutable release version or commit rather than main.
  4. Download the installer or binary to a local file first.
  5. Verify a publisher-provided cryptographic signature or SHA-256 checksum obtained through a trusted channel.
  6. Allow the user to inspect the script before execution and require explicit confirmation.
  7. Avoid administrator privileges unless the selected destination strictly requires them; prefer a user-owned binary directory where practical.
  8. Document the files and directories the installer changes and provide an uninstall procedure.

A safer pattern is:

bash
curl -fL --proto '=https' --tlsv1.2 \
  -o longbridge-install.sh \
  'https://raw.githubusercontent.com/longbridge/longbridge-terminal/IMMUTABLE_COMMIT/install'

echo 'EXPECTED_SHA256  longbridge-install.sh' | sha256sum -c -
less longbridge-install.sh
sh longbridge-install.sh

The commit and checksum must come from a verified official release; placeholders must not be used as actual values.

T03 · Remote Payload Retrieval and Execution

Error
Location
references/cli/overview.md:24
Finding

Duplicate Unverified Remote Installer Instruction in CLI Documentation

Content
View full analysis

Vulnerability Details

File Location: references/cli/overview.md, lines 24–26
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet

bash
# Any platform (install script)
curl -sSL https://github.com/longbridge/longbridge-terminal/raw/main/install | sh
# Installs `longbridge` binary to /usr/local/bin

Technical Analysis

This installation instruction creates the same mutable remote-code execution channel as the setup guide. It downloads the current contents of an installer from the upstream repository's main branch and executes them immediately with sh.

There is no immutable version pin, checksum, signature verification, or separation between retrieval and execution. The documentation states that the script installs a binary into /usr/local/bin, a location that is commonly system-wide and may require elevated privileges depending on ownership and platform configuration. The instruction does not explicitly invoke sudo, so privilege escalation is not independently confirmed; however, users may be prompted or may rerun the command with elevated privileges to make the installation succeed.

The behavior is not the least-privileged installation method available. The same document already presents Homebrew as the recommended macOS installation route, and verified release artifacts could cover other platforms without executing a mutable script directly from the network.

Attack Path

  1. An attacker gains control over the upstream main-branch installer or the content delivered by its URL.
  2. The attacker inserts arbitrary shell operations into the installer.
  3. A user or agent copies and runs the command from the CLI overview.
  4. The downloaded response is passed directly to sh, with no opportunity for integrity validation.
  5. Attacker-controlled commands execute under the invoking account.
  6. If the installation is performed with administrator privileges to write into `/usr/loc ...[truncated 581 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | sh installation command.
  2. Direct users to signed and versioned package-manager distributions where available.
  3. For unsupported platforms, link to an immutable release artifact rather than a mutable branch.
  4. Publish SHA-256 checksums and preferably cryptographic signatures for every release.
  5. Require users to download and verify the artifact before executing or installing it.
  6. Prefer installation into a user-owned directory unless system-wide installation is explicitly needed.
  7. Clearly disclose every destination and configuration file modified by the installer.
  8. Add explicit guidance not to run the installer as root unless independently verified and strictly necessary.

A hardened workflow should follow this sequence:

bash
curl -fL --proto '=https' --tlsv1.2 -o longbridge.tar.gz \
  'https://github.com/longbridge/longbridge-terminal/releases/download/VERSION/longbridge-PLATFORM.tar.gz'

echo 'EXPECTED_SHA256  longbridge.tar.gz' | sha256sum -c -
tar -tzf longbridge.tar.gz

After verification, the binary should be extracted and copied to an appropriate user-owned location. The version, platform name, and checksum must be replaced with values from a verified official release.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (23)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger scope is excessively broad: it activates on virtually any stock-related request, any ticker mention, and portfolio/account language. In an agent environment, this can cause the skill to intercept benign or ambiguous conversations and steer them into finance-specific workflows, increasing the chance of unnecessary sensitive-data access or unintended tool use.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The | sh construct is especially dangerous because it removes the user's opportunity to inspect the downloaded content before execution and enables seamless arbitrary command execution. In an AI-agent and trading CLI context, this is more dangerous because users may run commands suggested by automation on machines that also hold financial credentials and session tokens.

Content

Scanner excerpt · references/cli/overview.md (reported line 25)May include surrounding context.

brew install --cask longbridge/tap/longbridge-terminal

Any platform (install script)

curl -sSL https://github.com/longbridge/longbridge-terminal/raw/main/install | sh

Installs longbridge binary to /usr/local/bin

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/rust-sdk/types.md (reported line 206)May include surrounding context.

use longbridge::quote::SecuritiesUpdateMode;

SecuritiesUpdateMode::Add // Append securities SecuritiesUpdateMode::Remove // Remove securities SecuritiesUpdateMode::Replace // Replace all

text

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Piping downloaded content directly into sh removes the user's opportunity to inspect what will run and turns a remote content fetch into immediate code execution. This is especially risky in a setup guide for developer and AI-tool integration workflows, because it encourages broad adoption of a one-line command that could be abused for full local compromise if the upstream source is altered.

Content

Scanner excerpt · references/setup.md (reported line 10)May include surrounding context.

brew install --cask longbridge/tap/longbridge-terminal

Any platform

curl -sSL https://github.com/longbridge/longbridge-terminal/raw/main/install | sh

text

Authenticate:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow explicitly instructs pulling positions whenever the user asks about 'my portfolio' but does not require a privacy warning, consent check, or data-minimization step. Because positions and account-related information are sensitive financial data, automatic retrieval can expose private holdings unnecessarily or in response to ambiguous prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation instructs users to fetch and immediately execute a remote script via curl ... | sh without any integrity verification, pinning, or warning. This creates a supply-chain and remote code execution risk: if the remote content, transport, repository, or upstream account is compromised, users may execute attacker-controlled shell code on their systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file documents that an OAuth session token is stored locally at a fixed path but gives no guidance on protecting that credential or its file permissions. On shared, multi-user, or poorly secured systems, local token storage can enable session theft and unauthorized API access if the file is exposed.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · references/mcp.md (reported line 35)May include surrounding context.

md
### OAuth Authorization Flow

1. Add the config and call any tool — this triggers the OAuth flow
2. Client opens a browser tab to Longbridge login & consent page
3. Sign in with your Longbridge account and approve scopes
4. Credentials are stored by the client; tokens refresh automatically

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The documentation states that all connected MCP tools are automatically exposed and that the AI can directly inspect and call all tools, which implies broad default capability exposure. In a skill that covers portfolio access, market data, and potentially order placement, this increases the risk of over-privileged tool use or unintended execution of sensitive trading/account actions if the client or model lacks strong confirmation and per-tool authorization controls.

Content

Scanner excerpt · references/mcp.md (reported line 51)May include surrounding context.

md
## Available MCP Tools

When the MCP server is connected, available tools are automatically exposed to the AI — no hardcoded list needed. The AI can directly inspect and call all tools.

If you need to know what tools are available, ask the AI to list the connected MCP tools, or check the official docs: https://open.longbridge.com

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/python-sdk/overview.md (reported line 34)May include surrounding context.

Register once:

bash
curl -X POST https://openapi.longbridge.com/oauth2/register \
  -H "Content-Type: application/json" \
  -d '{"client_name":"My App","redirect_uris":["http://localhost:60355/callback"],"grant_types":["authorization_code","refresh_token"],"response_types":["code"]}'
# Response: {"client_id": "your-client-id", ...}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file includes examples for submitting, replacing, and canceling live orders, which can directly affect user assets and are potentially irreversible once sent to a broker. The section documents the API calls but does not warn readers that these examples may place or modify real trades or that they should verify environment/account context before use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This file is titled and structured as a quote/market-data reference, but it also documents creating, updating, and deleting watchlist groups, which are account-affecting write operations rather than quote retrieval. That expands behavior beyond the apparent read-oriented QuoteContext purpose presented by the surrounding documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation shows live order submission, replacement, and cancellation flows without an explicit warning that these calls can execute real trades against a brokerage account. In a skill explicitly triggered for trading, portfolio, CLI, and SDK tasks, users or downstream agents may copy examples directly into production-like environments and unintentionally place or modify real market orders.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The setup documentation instructs users to download and immediately execute a remote script with no integrity verification, pinning, or warning to inspect the script first. This creates a supply-chain execution path where a compromised GitHub account, repository, branch, or network path could lead to arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
96% confidence
Finding

This line fetches an external script from GitHub and executes it in the shell, creating a direct trust boundary violation. Because the content is remote and mutable, any compromise of the source or delivery path can turn installation into arbitrary code execution on the user's machine.

Content

Scanner excerpt · references/cli/overview.md (reported line 25)May include surrounding context.

brew install --cask longbridge/tap/longbridge-terminal

Any platform (install script)

curl -sSL https://github.com/longbridge/longbridge-terminal/raw/main/install | sh

Installs longbridge binary to /usr/local/bin

text

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The overview says the CLI probes geotest.lbkrs.com on startup and caches the result, but it does not explicitly warn that startup performs a network request and stores region-detection data locally. This is a user-impacting behavior related to privacy and system state that should be disclosed more clearly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The examples retrieve sensitive financial information including order history, executions, account balances, and cash flows. The documentation presents these calls without any warning that they expose private account and transaction data, which is relevant user disclosure for a skill description handling financial records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file includes example code that loads credentials via Config::from_apikey_env()?, which implies access to sensitive environment variables. The surrounding documentation does not warn readers that the example depends on locally stored API keys or that credentials will be read from the environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The markdown documents direct HTTP calls to content and filings endpoints, which transmit request data over the network. There is no accompanying warning that these examples contact external services and may send symbols or authenticated account-associated data to the API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example sets .language(Language::EN) as the configuration choice in documentation, which can be read as prescribing English output by default. The file does not mention that language is configurable or that users may choose a different locale, so it risks violating language/locale choice expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The example loads API credentials from environment variables without any note about secret handling, least-privilege, or avoiding credential exposure in logs, shells, and shared environments. While this is a common pattern, documentation for a trading SDK should warn that these credentials grant access to sensitive account and trading capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file explicitly documents Language::EN as the default language, which can be read as imposing a language choice without user opt-in. Under the policy rule, forcing a specific language without offering a choice is a natural-language locale concern.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
97% confidence
Finding

Fetching an external script from a live URL during setup is dangerous because the retrieved content can change over time and may be malicious if the source is compromised. In this skill context, users are likely to copy-paste setup commands directly, which increases the chance of unreviewed execution and makes the supply-chain risk more practical.

Content

Scanner excerpt · references/setup.md (reported line 10)May include surrounding context.

brew install --cask longbridge/tap/longbridge-terminal

Any platform

curl -sSL https://github.com/longbridge/longbridge-terminal/raw/main/install | sh

text

Authenticate:

Static analysis

No suspicious patterns detected.