Back to skill

Security audit

LongbridgeAssistant

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says, but it handles brokerage credentials and real portfolio data with weak storage and install safeguards.

Review this skill before installing. Use only a minimally scoped read-only Longbridge token, store ~/.longbridge/env with owner-only permissions, remove or replace the bundled personal alert rules and portfolio examples, and avoid publishing the package with real financial details. Pin and review dependencies before running setup.sh.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
setup.sh:17
Finding

Unpinned Third-Party Dependencies Are Installed at Runtime

Content
View full analysis
/dev/null; then echo "Installing Longbridge Python SDK..." pip3 install longbridge fi # Check matplotlib if ! python3 -c "import matplotlib" 2>/dev/null; then echo "Installing matplotlib..." pip3 install matplotlib fi ``` The documentation also directs users to install mutable package versions: ```bash pip install longbridge matplotlib ``` ### Technical Analysis The setup process installs `longbridge` and `matplotlib` without exact version constraints, package hashes, a lock file, or an explicitly trusted package index. Consequently, the code reviewed during this audit does not uniquely identify the code that will eventually be installed. If a dependency account, release process, package index, or transitive dependency is compromised, a future installation can retrieve malicious code even though the Skill itself remains unchanged. Python packages may execute build-system or installation logic during installation and arbitrary code when imported. The use of the standalone `pip3` executable also does not guarantee that dependencies are installed into the same Python environment used to run the Skill. ### Attack Path 1. An attacker compromises an upstream dependency, one of its transitive dependencies, or the package publication account. 2. The attacker publishes a malicious version under the legitimate package name. 3. A user runs `setup.sh` or follows the documented unpinned `pip install` command. 4. Pip resolves and downloads the attacker-controlled release. 5. Malicious package code executes during installation or when `longbridge_skill.py` imports the package. 6. The payload runs with the ...[truncated 782 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
run.sh:7
Finding

Brokerage Credentials Are Stored and Imported Unsafely

Content
View full analysis
~/.longbridge/env echo 'export LONGBRIDGE_APP_SECRET="yourAppSecret"' >> ~/.longbridge/env echo 'export LONGBRIDGE_ACCESS_TOKEN="yourAccessToken"' >> ~/.longbridge/env ``` ### Technical Analysis The credential file contains the Longbridge application key, application secret, and access token in plaintext. The documented creation commands rely on the user's current umask and do not enforce mode `0600`, validate file ownership, or ensure that `~/.longbridge` is private. The runtime import is also overly broad. It exports every non-comment assignment present in the file rather than accepting only the three declared Longbridge variables. This permits a locally tampered configuration file to influence unrelated environment variables used by Python or its dependencies. Parsing through `xargs` is not a safe environment-file parser. Quoting, whitespace, backslashes, and shell-sensitive token characters may be transformed or split, resulting in credential corruption or unintended variables. Although the observed command does not directly evaluate file contents as shell commands, importing arbitrary variable names can still influence runtime behavior through variables such as Python module paths, proxy settings, certificate locations, or library-specific configuration. ### Attack Path 1. The user creates `~/.lon ...[truncated 1458 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
longbridge_skill.py:17
Finding

Distributable Package Contains User-Specific Financial Information

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (35)

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 34)May include surrounding context.

bash
export LONGBRIDGE_APP_KEY="你的 App Key"
export LONGBRIDGE_APP_SECRET="你的 App Secret"
export LONGBRIDGE_ACCESS_TOKEN="你的 Access Token"

步骤 3:安装本 Skill

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a securities portfolio assistant with stock holding retrieval, portfolio visualization, price alerts, and investment suggestions. However, the provided code chunk contains only what appears to be tar/archive metadata and extended attribute records, not Python logic implementing any of those capabilities. Because the actual supplied content does not demonstrate the declared behavior and instead appears unrelated to the stated purpose, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a stock portfolio assistant with real-time holdings access, market-specific visualization, alerts, and investment advice. However, the provided code chunk contains only file/archive metadata entries for PaxHeader/run.sh and no executable logic related to securities, APIs, portfolio analysis, charting, or alerts. This is therefore a material mismatch between the declared purpose and the actual supplied code behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a securities investment assistant with real-time holdings access, portfolio analysis, visualizations, and alerting features. However, the provided code chunk contains only file/archive metadata related to a shell script header and macOS provenance attributes. There is no observable logic for fetching holdings, processing stock data, generating charts, setting alerts, or providing recommendations. This is a material mismatch because the actual supplied content does not implement the declared primary purpose or capabilities.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
编辑 `longbridge_skill.py` 中的 `ALERTS` 字典:

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill description, usage instructions, examples, and warnings are presented only in Chinese, which indicates a fixed language/locale for user interaction. Under the policy, language constraints should either be optional via user choice or clearly justified as region-specific; this README provides neither.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The release notes instruct users to place brokerage API credentials directly into a shell env file and run the skill against live holdings data, but they provide no guidance on secret storage, file permissions, rotation, redaction, or handling of sensitive financial information. In an investment-assistant context, exposed tokens could allow unauthorized access to account data and potentially facilitate misuse of highly sensitive portfolio information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.