longbridge-quant
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on the
longbridgecommand-line interface to interact with market data and account information. It utilizes subcommands such askline,constituent,calc-index,positions, andquantto perform its core functions.\n- [EXTERNAL_DOWNLOADS]: Instructions are provided to install well-known and trusted Python packages (scikit-learn,pandas,numpy,statsmodels,scipy,arch,xgboost,lightgbm) necessary for quantitative research and machine learning. It also points to the official Navi language documentation for additional tooling.\n- [DYNAMIC_EXECUTION]: The skill generates and facilitates the execution of Python scripts for statistical analysis and Navi/Pine scripts for server-side quantitative computations. This allows for complex, user-defined analysis on financial time-series data.\n- [INDIRECT_PROMPT_INJECTION]: By processing external market data and financial reports, the skill exhibits an attack surface for indirect prompt injection. However, the data is treated as structured numerical input for analytical frameworks, which significantly mitigates the risk of adversarial instruction execution.
Audit Metadata