Tushare Data
zillionare/zillionare
面向中文自然语言的 Tushare 数据研究技能。用于把“看看这只股票最近怎么样”“帮我查财报趋势”“最近哪个板块最强”“北向资金在买什么”“给我导出一份行情数据”这类请求,转成可执行的数据获取、清洗、对比、筛选、导出与简要分析流程。适用于 A 股、指数、ETF/基金、财务、估值、资金流、公告新闻、板块概念与宏观数据等研究场景。
Verify a claim before stating it, and verify a test before trusting it.
$ npx skills add marketcalls/openalgo --skill verify -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install marketcalls/openalgo verify --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verify .claude/skills/verify && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "verify" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/verify into .claude/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/marketcalls/openalgo/tree/main/.claude/skills/verifyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add marketcalls/openalgo --skill verify -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install marketcalls/openalgo verify --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/verify .agents/skills/verify && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "verify" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/verify into .agents/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marketcalls/openalgo --skill verify -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install marketcalls/openalgo verify --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/verify .cursor/skills/verify && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "verify" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/verify into .cursor/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/marketcalls/openalgo.git --path .claude/skills/verify--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add marketcalls/openalgo --skill verify -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install marketcalls/openalgo verify --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/verify .gemini/skills/verify && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "verify" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/verify into .gemini/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install marketcalls/openalgo verifyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add marketcalls/openalgo --skill verify -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/verify .github/skills/verify && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "verify" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/verify into .github/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add marketcalls/openalgo --skill verify -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install marketcalls/openalgo verify --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/marketcalls/openalgo.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/verify .opencode/skills/verify && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "verify" agent skill from https://github.com/marketcalls/openalgo/tree/main/.claude/skills/verify into .opencode/skills/verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "verify", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
verifyVerify a claim before stating it, and verify a test before trusting it.
Verify is an agent skill from marketcalls/openalgo. Verify a claim before stating it, and verify a test before trusting it. Use before asserting that a security control holds, that a pattern is safe, that a bug is fixed, or that a test guards a fix. Also use when reporting audit or scanner findings, when a grep "found nothing", when a lint or test count looks clean, and before telling a user that something is or is not a vulnerability.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `redaction_check.py`).
It sits in Business, Finance & HR, covering Trading and backtesting. It works with Python. The repository describes itself as: Open Source Algo Trading Platform for Everyone. The licence is AGPL-3.0.
Read from SKILL.md and the folder at commit 1dcfff5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships script files (Python), which the agent can run.
Shell commands in SKILL.md call:
uvgitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use uv and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Verify loads about 1.5k tokens when it runs. Until then it costs about 99 tokens; SKILL.md has 847 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from marketcalls/openalgo at commit 1dcfff5, republished under its AGPL-3.0 licence (© marketcalls). 847 words, ~1,489 tokens.
.claude/skills/verify/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Every high-severity finding this repo has produced came from executing something. Every wrong claim came from reading something and reasoning about it.
The rules below are cheap. Skipping them is what produces a confident, wrong answer that a maintainer then acts on.
A regex, a redaction filter, a permission mask or a capability gate is code. Run it against a realistic value and look at the output.
What happens when you don't. utils/logging.py redacts key-value shapes.
Reading the pattern suggested "Feed Token: {t}" leaked, so nine call sites
were reported as leaks. Executing it showed the alternation contains a bare
token, which matches Token: and redacts the value. The finding was wrong in
the direction that wastes a maintainer's time.
The same run showed "Access Token obtained: {t}" genuinely leaks, because a
word sits between the keyword and the colon. Neither result was predictable by
inspection.
uv run python .claude/skills/verify/redaction_check.py \
"Access Token obtained: {t}" "eyJhbGciOiJIUzI1NiJ9.SEKRET.sig"Prints LEAKS or redact and exits non-zero when the secret survives, so it
drops into a loop or a test.
Corollary: whether a log line leaks depends on data you have not read yet.
?susertoken= and ?token= redact; ?Value1= and ?jKey= do not. You cannot
judge a logged URL without opening the code that builds it and learning the real
parameter name.
A test that passes proves nothing until you have seen it fail. Revert the fix, or neuter the guard it depends on, and confirm the test goes red. Then restore.
What happens when you don't. A StrategyBuilder test asserted a tile was
absent after an identity reset. It passed. It also passed against the exact bug
it was written to catch, because the assertion raced a 400ms debounce that
legitimately re-rendered the tile.
Two ways this goes wrong, both seen here:
is_stale = qty != 0 and updated_at < boundary) instead of calling the
function under test. It is then testing Python's < operator.When disabling a guard to prove a test, target the exact line. A blind
replace(..., 1) hits the first match, which may be a different, pre-existing
guard, and then the "proof" proves nothing.
A grep that returns nothing is not evidence of absence. It is evidence about your pattern.
What happens when you don't. Searching broker/ for credential variable
names inside f-strings found and fixed the direct cases. It was structurally
incapable of seeing the larger class, where the secret rides inside something
else that gets logged:
httpx.HTTPStatusError embeds the full URL, so a
credential in the URL path leaked on every 4xx, exactly the wrong-credential
case)Before concluding a class is clear, ask what a leak would look like if the secret were never named in the log statement, then search for that.
A tool's output is meaningless without its prior value. Capture the count on
HEAD, apply the change, capture it again.
uv run ruff check <paths> | grep -oE "Found [0-9]+ errors"
git stash -q && uv run ruff check <paths> | grep -oE "Found [0-9]+ errors"; git stash pop -qTwo traps specific to this repo:
F401 is in the ruff ignore list (pyproject.toml). An orphaned
import logging will not be flagged. Verify unused imports by grep..tsx reports a format error,
including files you never touched. Run the check on an untouched file first to
establish that the error is environmental.Reporting a safe site as fixed inflates the apparent severity of your work and teaches the reader that the report cannot be trusted.
Of seven sites reported as leaking WebSocket URLs, two leaked and five were already redacted. The fix touched the two. The other five were left alone and named as false positives in the review. Churning them would have produced a diff that looked like a fix and taught nobody anything.
State plainly which of the reported items were real. When a scanner is the source, expect false positives and triage each one:
NullPool check failed on engine_factory.py's own docstring.is_session_valid()
in the function body read as unprotected.0o666.If a tool times out, is not installed, or is skipped, say so and treat the area
as unverified. detect-secrets timing out means secret scanning did not happen,
regardless of the exit code of the run that contained it.
Correct it in one plain sentence with the evidence, and carry on. A wrong claim that gets quietly dropped is worse than one that gets corrected, because the maintainer may already have acted on it.
© marketcalls, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in .claude/skills/verify of marketcalls/openalgo.
Open the folder on GitHubat commit 1dcfff5
Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Verify this skillmarketcalls/openalgo | 2.8k | — | ~1.5k | Automated safety check: Pass | AGPL-3.0 | |
| Tushare Datazillionare/zillionare | 321 | 2 repos | ~2.3k | Automated safety check: Pass | None | |
| Kalshi Traderyanfrigo/kalshi-ai-trading-bot | 614 | — | ~3.4k | Automated safety check: Pass | MIT | |
| Polymarket Tennislivetennisapi/livetennisapi-mcp | 152 | — | ~3k | Automated safety check: Pass | MIT | |
| Quant Backtestjoemccann/market-data-warehouse | 183 | — | ~2.1k | Automated safety check: Pass | None | |
| Qmt Inner Backtestdfkai/xtquantai | 164 | — | ~1.8k | Automated safety check: Pass | MIT |
zillionare/zillionare
面向中文自然语言的 Tushare 数据研究技能。用于把“看看这只股票最近怎么样”“帮我查财报趋势”“最近哪个板块最强”“北向资金在买什么”“给我导出一份行情数据”这类请求,转成可执行的数据获取、清洗、对比、筛选、导出与简要分析流程。适用于 A 股、指数、ETF/基金、财务、估值、资金流、公告新闻、板块概念与宏观数据等研究场景。
ryanfrigo/kalshi-ai-trading-bot
The disciplined process for autonomously and profitably trading the live Kalshi account on each /loop tick, with Claude as the decision-maker.
livetennisapi/livetennisapi-mcp
Build observe-only Polymarket and Kalshi tennis market tooling on the polymarket-tennis Python package (MIT) plus the Live Tennis API free tier.
joemccann/market-data-warehouse
Institutional-grade Python backtesting framework builder for Codex.
dfkai/xtquantai
根据策略描述、研报 PDF 或截图,解读因子/选股逻辑,基于 scripts/daily-factors-backtest.py 框架生成 QMT 内置日频因子回测脚本。用户提到 QMT 内置回测、因子选股回测、截面因子、 研报复现、handlebar 回测、afterinit 预计算信号时使用。
gauss314/skills
Academic backtesting framework for quantitative research. An agent skill from gauss314/skills.
marketcalls/openalgo
Integrate a new Indian broker into OpenAlgo, or modify an existing broker plugin.
marketcalls/openalgo
Audit a change for resource leaks in OpenAlgo — file descriptors AND unbounded memory growth.
marketcalls/openalgo
Build, edit or debug an OpenAlgo Flow workflow - the no-code node graph at /flow.
marketcalls/openalgo
Write an OpenScript study or strategy for OpenAlgo, and install it into strategies/openscript/ only after it compiles.
marketcalls/openalgo
Run OpenAlgo's periodic security audit across backend, frontend, database, cache, routes and dependencies, producing a dated xlsx report.
marketcalls/openalgo
Bump a version in the OpenAlgo repo. An agent skill from marketcalls/openalgo.
Works with
Categories
Verify a claim before stating it, and verify a test before trusting it. Verify is an agent skill from marketcalls/openalgo. Verify a claim before stating it, and verify a test before trusting it.
Verify fits situations like: reporting audit; scanner findings; A grep found nothing; test count looks clean.
Run `npx skills add marketcalls/openalgo --skill verify -a claude-code`. Or copy the skill folder (.claude/skills/verify in marketcalls/openalgo) into .claude/skills/verify in your project. Claude Code loads it when a task matches its description.
Run `npx skills add marketcalls/openalgo --skill verify -a codex`. Or copy the skill folder (.claude/skills/verify in marketcalls/openalgo) into .agents/skills/verify in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marketcalls/openalgo --skill verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify, .gemini/skills/verify, .github/skills/verify and .opencode/skills/verify in your project.
Going by SKILL.md and its folder, Verify needs Python for the scripts in its folder and the command-line tools its instructions call (uv and git). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use uv and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Verify is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Verify: Tushare Data (zillionare/zillionare, 321 stars), Kalshi Trade (ryanfrigo/kalshi-ai-trading-bot, 614 stars), Polymarket Tennis (livetennisapi/livetennisapi-mcp, 152 stars) and Quant Backtest (joemccann/market-data-warehouse, 183 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
marketcalls (a GitHub user) maintains it in marketcalls/openalgo, which has 2,808 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on October 9, 2026.
Source: marketcalls/openalgo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.