Back to skill

Security audit

Longbridge

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent Longbridge connector that exposes expected financial-account reads through a scoped OOMOL CLI integration, with no evidence of hidden exfiltration or destructive behavior.

Install only if you trust OOMOL and intend to use an OOMOL-connected Longbridge account. Treat account balances, positions, orders, executions, cash flow, and portfolio analytics as private financial data, and ask the agent to retrieve only the specific records needed for your task. Review the one-time CLI install/login steps before allowing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The instruction to use this skill for 'ANY Longbridge request' is overly broad and can cause the agent to route a wide range of tasks through a powerful connector without sufficient task-level constraints. In context, this is more dangerous because the skill includes access to sensitive account data and some state-affecting operations, increasing the chance of unnecessary exposure or misuse.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill exposes account balances, positions, cash flows, orders, executions, and portfolio analytics without clearly warning that these are sensitive financial records. In this context, the absence of a privacy warning and access minimization guidance increases the risk that an agent retrieves more personal financial data than necessary for the user's request.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.