Durable Objects
hodgef/apiker
Create and review Cloudflare Durable Objects. An agent skill from hodgef/apiker.
Audit a change for resource leaks in OpenAlgo — file descriptors AND unbounded memory growth.
$ npx skills add marketcalls/openalgo --skill fd-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install marketcalls/openalgo fd-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/fd-audit .claude/skills/fd-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fd-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/fd-audit into .claude/skills/fd-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fd-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/marketcalls/openalgo/tree/main/.claude/skills/fd-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add marketcalls/openalgo --skill fd-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install marketcalls/openalgo fd-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/fd-audit .agents/skills/fd-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fd-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/fd-audit into .agents/skills/fd-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fd-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marketcalls/openalgo --skill fd-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install marketcalls/openalgo fd-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/fd-audit .cursor/skills/fd-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fd-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/fd-audit into .cursor/skills/fd-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fd-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/marketcalls/openalgo.git --path .claude/skills/fd-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add marketcalls/openalgo --skill fd-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install marketcalls/openalgo fd-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/fd-audit .gemini/skills/fd-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fd-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/fd-audit into .gemini/skills/fd-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fd-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install marketcalls/openalgo fd-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add marketcalls/openalgo --skill fd-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/fd-audit .github/skills/fd-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fd-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/fd-audit into .github/skills/fd-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fd-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marketcalls/openalgo --skill fd-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install marketcalls/openalgo fd-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/fd-audit .opencode/skills/fd-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fd-audit" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/fd-audit into .opencode/skills/fd-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fd-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fd-auditAudit a change for resource leaks in OpenAlgo — file descriptors AND unbounded memory growth.
Fd Audit is an agent skill from marketcalls/openalgo. Audit a change for resource leaks in OpenAlgo — file descriptors AND unbounded memory growth. Run after building a feature or fixing anything that touches databases, WebSockets or streaming, threads or executors, subprocesses, files, sockets, caches, or module-level registries. Also use when the user reports "too many open files", refused DB connections, dropped sockets, rising RSS, or a Gunicorn worker that degrades over hours or days.
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `soak.py`).
It sits in Backend & APIs, covering Realtime and WebSockets and Trading and backtesting. It works with SQLite and DuckDB. The repository describes itself as: Open Source Algo Trading Platform for Everyone. The licence is AGPL-3.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 12e1114. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fd Audit loads about 2.1k tokens when it runs. Until then it costs about 112 tokens; SKILL.md has 1,031 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from marketcalls/openalgo at commit 12e1114, republished under its AGPL-3.0 licence (© marketcalls). 1,031 words, ~2,131 tokens.
.claude/skills/fd-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.OpenAlgo runs production as a single long-lived Gunicorn worker
(--worker-class eventlet -w 1). It never restarts between deploys, so anything
leaked once per request accumulates until the process dies. There is no second
worker to absorb the failure and no natural recycling point.
Two failure modes, same root cause — unbounded growth in a process that never restarts:
| Symptom | Ceiling | |
|---|---|---|
| Descriptors | OSError: [Errno 24] Too many open files, refused DB connections, dropped WebSocket clients | OS ulimit -n (often 1024–65535) |
| Memory | Rising RSS, swap thrash, OOM-killer, gradual latency creep | Host RAM |
Audit the change you just made, not the whole repo.
If the change touches none of these, the audit is done. Say so and move on.
Descriptor-holding: SQLAlchemy engines/sessions · DuckDB connections · HTTP
clients · WebSockets · ZeroMQ sockets · subprocesses · files · raw sockets ·
threads and executors · inotify/selectors
Memory-holding: module-level dicts, lists and sets · caches · event-bus subscriptions · SocketIO rooms · registries keyed by symbol/user/strategy · retained DataFrames · closures capturing large objects
SQLite engines. Only via database.engine_factory.create_db_engine(), which
applies NullPool. Never create_engine() directly, never StaticPool — a
shared connection has its cursor state corrupted under concurrency, producing
"bad parameter or other API misuse" and "cannot commit - SQL statements in progress".
DuckDB is separate. database/historify_db.py calls duckdb.connect()
directly — it does not go through engine_factory and NullPool does not
apply. Each connection is an FD plus a memory arena. Use a context manager or
guarantee .close(); a DuckDB connection left open also holds its buffer pool.
Sessions. Every scoped_session is either registered in the app.py
teardown_appcontext handler or used as with db_session() as session:. A
scoped_session created in a module and never .remove()d holds a connection
per green thread forever. Existing cleanup layers to match: app.py teardown,
traffic_logger.py logs_session.remove() in a finally,
security_middleware.py for the banned-IP WSGI path, and teardown handlers in
blueprints/traffic.py and blueprints/security.py.
HTTP. Use the shared utils/httpx_client.get_httpx_client(). A per-call
httpx.Client() opens a fresh connection pool and leaks it unless closed; the
shared client is what keeps HTTP/2 keep-alive to broker APIs working. Always
pass an explicit timeout= — a hung request holds its socket indefinitely,
which is a slow leak that looks like a hang.
WebSocket adapters. Close before reconnect. A reconnect path that opens a new socket without closing the old one leaks one descriptor per retry — and retries run unbounded during a broker outage, which is exactly when you cannot afford it.
ZeroMQ. Sockets closed on shutdown and adapter teardown; cleanup_zmq() in
disconnect(). Never create a context per call. Read the SUB-binds/PUBs-connect
invariant in CLAUDE.md before changing any bind/connect.
Subprocesses. Write to a log file, not PIPE, and .wait()-reap. An
unreaped child leaves a zombie plus its pipe FDs; undrained PIPE output
deadlocks the child once the buffer fills. Note telegram_bot_service's kaleido
renderer spawns a real OS thread and an image-export subprocess — both must be
joined/reaped on every path.
Threads and executors. Shared module-level singletons. Never a
ThreadPoolExecutor per call or per request — each holds threads plus an
internal control pipe until shut down. Under eventlet, threading.local() maps
to green threads, so per-green-thread state accumulates with connection count,
not with CPU count.
Files. with blocks. Temp files cleaned up via tempfile context managers.
Descriptors have a hard OS ceiling that surfaces loudly. Memory degrades quietly, so it needs deliberate checking.
Every cache needs a bound. A plain dict used as a cache never evicts. Use
cachetools.TTLCache(maxsize=..., ttl=...) — the codebase already standardises
on it (database/telegram_db.py, latency_db.py, token_db_backup.py,
flow_db.py). Both parameters matter: maxsize bounds memory, ttl bounds
staleness.
Known unbounded collections to model your review on — check whether yours looks like these:
services/option_symbol_service.py:_STRIKES_CACHE — plain dict keyed by (symbol, exchange, expiry, type), no eviction. Grows with every distinct instrument queried.blueprints/python_strategy.py:RUNNING_STRATEGIES / STRATEGY_CONFIGS — keyed by strategy id; correct only if entries are deleted on stop, not just on graceful stop.websocket_proxy/broker_factory.py:_POOLED_ADAPTERS and services/order_update_service.py:_ADAPTERS — keyed by {broker}_{user_id}; bounded in practice because OpenAlgo is single-user, but verify entries are removed on disconnect.Registries need a matching removal. For every dict[key] = value,
join_room, subscribe, append, or add on module-level state, find the
line that removes it — and confirm it runs on the error path too. Subscription
without unsubscription is the most common memory leak in an event-driven app.
Ask "what is the key space?" A dict keyed by user id is bounded (one user). Keyed by symbol, strategy id, request id, or session id, it is not. Unbounded key space plus no eviction equals a leak, however small each entry is.
Retained DataFrames. History and option-chain paths build large pandas objects. Don't stash them on module-level state or in a closure that outlives the request.
For each resource, confirm release on all three, not just the happy one:
finally or a context manager, not a trailing close statementRetry loops are the most common real leak: the code closes on success and on
error, but the continue in the retry branch skips the close.
Static review misses leaks that only appear under repetition. When a leak is suspected rather than hypothetical:
# Descriptor count for the running worker, sampled over time
PID=$(pgrep -f "gunicorn.*app:app" | head -1)
lsof -p "$PID" | wc -l # macOS and Linux
ls /proc/$PID/fd | wc -l # Linux, cheaper
# What kind of descriptor is growing
lsof -p "$PID" | awk '{print $5}' | sort | uniq -c | sort -rn | head
# RSS over time
ps -o rss=,vsz= -p "$PID"Take a baseline, drive the suspect path in a loop (100+ iterations), sample again. A flat count after N iterations is the only real proof. A count that rises and plateaus is a cache filling; one that rises linearly is a leak.
For memory specifically, tracemalloc around the suspect path gives allocation
sites directly:
import tracemalloc
tracemalloc.start()
snap1 = tracemalloc.take_snapshot()
# ...drive the path N times...
snap2 = tracemalloc.take_snapshot()
for s in snap2.compare_to(snap1, "lineno")[:10]:
print(s)If everything holds, state which resources you checked and that each is released on all paths — and say whether you verified statically or by measurement.
If you find a leak, do not silently fix it and do not proceed with other work. Report:
Then ask the user to approve the fix before applying it.
© marketcalls, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .claude/skills/fd-audit of marketcalls/openalgo.
Open the folder on GitHubat commit 12e1114
Fd Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fd Audit this skillmarketcalls/openalgo | 2.8k | — | ~2.1k | Automated safety check: Pass | AGPL-3.0 | |
| Durable Objectshodgef/apiker | 127 | 4 repos | ~1.5k | Automated safety check: Pass | MIT | |
| Web3 PolymarketPolymarket/agent-skills | 192 | 1 repos | ~2k | Automated safety check: Pass | None | |
| Cryptofeed2025Emma/vibe-coding-cn | 23k | 1 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Tiger Brokers C++ OpenAPI SDKqusong0627/QuantMind | 1.7k | — | ~942 | Automated safety check: Pass | Apache-2.0 | |
| Polymarket2025Emma/vibe-coding-cn | 23k | 1 repos | ~1.6k | Automated safety check: Pass | MIT |
hodgef/apiker
Create and review Cloudflare Durable Objects. An agent skill from hodgef/apiker.
Polymarket/agent-skills
Polymarket integration for prediction market trading on Polygon.
2025Emma/vibe-coding-cn
Cryptofeed - Real-time cryptocurrency market data feeds from 40+ exchanges.
qusong0627/QuantMind
Guides an agent through the Tiger Brokers OpenAPI C++ SDK for build setup, market data, orders and real-time push, defaulting to paper trading.
2025Emma/vibe-coding-cn
Comprehensive Polymarket skill covering prediction markets, API, trading, market data, and real-time WebSocket data streaming.
marketcalls/openalgo-charts
Build a full trading terminal on openalgo-charts - symbol search, interval switcher, chart-type picker, indicator menu, drawing rail with clipboard, live OpenAlgo REST plus WebSocket data behind a…
marketcalls/openalgo
Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.
marketcalls/openalgo
Build, edit or debug an OpenAlgo Flow workflow - the no-code node graph at /flow.
marketcalls/openalgo
Write an OpenScript study or strategy for OpenAlgo, and install it into strategies/openscript/ only after it compiles.
marketcalls/openalgo
Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.
marketcalls/openalgo
Verify a claim before stating it, and verify a test before trusting it.
marketcalls/openalgo
Bump a version in the OpenAlgo repo. An agent skill from marketcalls/openalgo.
Categories
Audit a change for resource leaks in OpenAlgo — file descriptors AND unbounded memory growth. Fd Audit is an agent skill from marketcalls/openalgo. Audit a change for resource leaks in OpenAlgo — file descriptors AND unbounded memory growth.
Fd Audit fits situations like: the user reports too many open files; refused DB connections; dropped sockets; A Gunicorn worker that degrades over hours.
Run `npx skills add marketcalls/openalgo --skill fd-audit -a claude-code`. Or copy the skill folder (.claude/skills/fd-audit in marketcalls/openalgo) into .claude/skills/fd-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add marketcalls/openalgo --skill fd-audit -a codex`. Or copy the skill folder (.claude/skills/fd-audit in marketcalls/openalgo) into .agents/skills/fd-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marketcalls/openalgo --skill fd-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fd-audit, .gemini/skills/fd-audit, .github/skills/fd-audit and .opencode/skills/fd-audit in your project.
Going by SKILL.md and its folder, Fd Audit needs Python for the scripts in its folder. Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Fd Audit is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Fd Audit: Durable Objects (hodgef/apiker, 127 stars), Web3 Polymarket (Polymarket/agent-skills, 192 stars), Cryptofeed (2025Emma/vibe-coding-cn, 23k stars) and Tiger Brokers C++ OpenAPI SDK (qusong0627/QuantMind, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
marketcalls (a GitHub user) maintains it in marketcalls/openalgo, which has 2,817 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.
Source: marketcalls/openalgo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.