HKUDS/Vibe-Trading
58.0
Weak · 18 September 2026
443k
lines of production code
Python
with TypeScript
1
measurement over time
What this system is
Vibe-Trading is an open-source, AI-driven quantitative finance platform that combines autonomous research agents with a comprehensive backtesting and live-trading infrastructure. It enables users to execute institutional-grade financial analysis, including alpha factor discovery, valuation modeling, and cross-market strategy simulation across equities, crypto, and forex. The system features a modular architecture with strict governance, including mandate-gated autonomous trading, tamper-evident audit logging, and deterministic evaluation harnesses to ensure research integrity and safety.
Features
Add MetaTrader 5 broker connector
Introduces a new connector for MetaTrader 5 (MT5) brokers, enabling trading via a local Windows terminal. The implementation includes configuration management for paper (demo) and live accounts, order placement and cancellation logic with size guards, and read operations for account snapshots, positions, and historical bars. It also provides symbol normalization and mandate classification to distinguish between forex pairs and CFDs.
agent/src/trading/connectors/mt5 · high confidence
Add Mootdx-based A-share data fetching capability
A new Python module, a\_mootdx\_fetcher.py, has been added to the agent/skills/ashare-mootdx/references directory. This module provides a standard adapter for fetching A-share market data using the Mootdx library, offering functions to retrieve daily historical bars, real-time quotes, and a list of all A-share stocks. It handles market detection for Shanghai and Shenzhen exchanges, maps frequency codes, and includes a batch fetching utility with built-in rate limiting and error handling to ensure robust data retrieval without requiring API keys.
agent/skills · high confidence
Add Shoonya (Finvasia) trading connector for Indian markets
Introduces a new connector for Shoonya (Finvasia), providing read-only and paper-trading capabilities for NSE/BSE equities, F&O, currency, and commodity markets. The implementation wraps the NorenRestApiPy SDK, supporting TOTP-based authentication and exposing specific trading profiles (paper-sdk, paper-trade, live-readonly) that are structurally capped at paper for order placement due to the broker's lack of a runtime sandbox. It also includes classification logic to distinguish read vs. write operations and handles interval mapping for historical data requests.
agent/src/trading/connectors/shoonya · high confidence
Add Toss Securities (토스증권) read-only trading connector
Introduces a new connector for Toss Securities that provides read-only access to account snapshots, holdings, quotes, and historical candle data via the official Toss Invest Open API. The implementation enforces a strict read-only mode for all profiles, hard-refusing order placement and cancellation requests because the API lacks a verifiable sandbox or paper/live discriminator. It includes configuration management for client credentials and account sequence, along with classification rules to ensure write operations are safely blocked.
agent/src/trading/connectors/toss · high confidence
Add Zerodha Kite Connect trading connector
Introduces a new connector for the Zerodha Kite Connect API, enabling access to Indian equity and F&O markets (NSE/BSE). The implementation provides read-only capabilities for historical OHLCV data, quotes, positions, and holdings, alongside a locally simulated paper-trading mode for order placement. Live order placement is explicitly disabled to prevent accidental real-money transactions, as the underlying API lacks a sandbox environment. The connector handles API-specific constraints, such as paginating historical data requests within Kite's daily limits and rejecting unsupported intervals like 4h.
agent/src/trading/connectors/zerodha · high confidence
Add anonymous traffic analytics and PyPI install stats to the wiki footer
The wiki now displays aggregate traffic and package installation counts in its footer. A new middleware classifies incoming requests as human, AI agent, or generic bot based on User-Agent strings and stores daily counts in a D1 database, while a new API endpoint aggregates these all-time web stats and fetches PyPI install data for the \vibe-trading-ai\ package, caching the result in D1 to handle upstream failures gracefully.
wiki/functions · high confidence
Agent reliability, observability, and output discipline overhaul
The agent core has been significantly hardened and expanded to improve reliability, transparency, and output quality. Context management now uses a five-layer system (including context collapse and iterative updates) to handle long runs more efficiently. A new progress channel provides structured tool progress and heartbeat keepalives, ensuring the UI remains responsive during long-running tasks. Output discipline is enforced via strict system prompt principles requiring every number to be sourced to a tool call, carrying an 'as-of' timestamp, and stopping when sufficient evidence is found. The tool registry now reports partial construction failures, and the trace writer has been upgraded to use durable sidecar files for large payloads, ensuring trace integrity even after crashes. Additionally, the skills loader now supports user-created skills, progressive section loading, and categorization.
agent/src/agent · high confidence
Automated Alpha Library generation with social card validation
A new build script (wiki/scripts/build\_alpha\_library.py) now automatically renders the Alpha Library wiki section from a manifest, producing individual HTML pages for each alpha and zoo overview pages with strict Content-Security-Policy headers and auto-escaped content. Additionally, a validation script (wiki/scripts/check\_social\_cards.py) ensures the Alpha Library landing page includes the correct 1200x630 social card metadata for Open Graph and Twitter.
wiki/scripts · high confidence
CLI slash commands and self-update mechanism
The CLI now uses a structured slash-command system (registered in \agent/cli/commands/slash\_router.py\) to manage interactive sessions and research workflows. Users can start and inspect finance research goals (\/goal\), manage persistent memory (\/memory\), browse session history and search (\/history\, \/search\), and access institutional research playbooks (\/comps\, \/dcf\, etc.) and scheduled research templates (\/playbook\). The chat interface also supports model switching (\/model\), clearing conversations (\/clear\), and analyzing trade journals (\/journal\). Additionally, a new \vibe-trading update\ command allows users to self-upgrade the package from PyPI, with logic to detect and handle editable or checkout installs safely.
agent/cli/commands · high confidence
Centralized configuration layer with Pydantic schema and runtime root migration
The agent now uses a unified, typed configuration system built on Pydantic models (EnvConfig, AgentConfig) to replace scattered os.getenv calls, ensuring all environment variables and agent settings are validated and centrally managed. This change introduces a dedicated runtime root (\~/.vibe-trading by default) for user state (sessions, runs, uploads), including an automatic migration module that safely moves legacy code-relative state to the new location. It also adds security hardening by sanitizing session overrides to prevent untrusted API callers from injecting MCP server definitions, and provides a thread-safe singleton accessor for configuration access.
agent/src/config · high confidence
Executable valuation models with strict input validation
The valuation engine now includes executable modules for Discounted Cash Flow (DCF), comparable companies (comps), and three-statement projections, replacing previous non-executable documentation. These models enforce a strict input discipline: any missing required field or non-finite value (such as negative share counts or invalid financial inputs) causes the model to refuse execution with a descriptive error, preventing silent defaults or misleading results. The system also introduces versioned model artifacts that capture input hashes, model versions, and explicit assumptions to ensure reproducibility and auditability of valuation outputs.
agent/src/quantlib/valuation · high confidence
Expanded language support with RTL and lazy loading
The frontend now supports eight languages (English, Chinese Simplified, Japanese, Korean, Arabic, Spanish, German, and Brazilian Portuguese) with Arabic enabling right-to-left layout mirroring. Language resources are loaded lazily on demand, and the application persists the user's choice in localStorage, falling back to English if a locale fails to load or is unavailable.
frontend/src/i18n · high confidence
Introduce Alpaca trading connector with mandate-gated live orders and optional TAP credential isolation
Adds a new Alpaca connector layer (agent/src/trading/connectors/alpaca) that exposes read-only access to account, positions, orders, quotes, and bars, plus order placement and cancellation. Live order placement is gated by a mandate requirement (alpaca-live-trade profile), while paper trading remains unrestricted. The connector supports both direct SDK usage and an opt-in TAP proxy mode for credential isolation, routing all broker egress through TAP when configured. Profiles distinguish between paper and live environments, ensuring correct API hosts and key usage.
agent/src/trading/connectors/alpaca · high confidence
Introduce Alpha Zoo framework with fundamental factors and strict benchmarking
The factors module now implements the Alpha Zoo architecture, providing a registry and operator layer for 460 alphas across five zoos (alpha101, gtja191, qlib158, academic, and fundamental). This release adds a new fundamental factor layer featuring PIT-safe SEC fundamentals (e.g., asset growth, earnings yield, gross profitability, ROE) as daily panels. To improve signal reliability, a strict benchmarking mode is introduced that requires a mandatory random control comparison and out-of-sample split to prevent false positives. The system also adds a head-to-head alpha comparison tool accessible via CLI, REST, and Web UI, and optimizes performance by integrating the Bottleneck library for faster rolling operators.
agent/src/factors · high confidence
Introduce Binance trading connector with read-only USD-M account snapshots
The agent now includes a new Binance trading connector that supports both spot and USD-M perpetual markets. It provides read-only access to account balances and market data, with a specific opt-in mode for USD-M that fetches strict account and position snapshots via the ccxt library. The connector enforces a structural separation between paper (testnet) and live environments using distinct API keys and hosts, and requires a user mandate for any live order placement capabilities.
agent/src/trading/connectors/binance · high confidence
Introduce Dhan broker connector for Indian markets
Added a new trading connector for Dhan, an Indian discount broker supporting NSE/BSE equities and F&O (NIFTY/BANKNIFTY options). The implementation includes read-only access to market data and account details, as well as a locally simulated paper-trading mode for order placement. Due to the lack of a runtime sandbox discriminator in the Dhan API, live order placement is not supported; users can only access live data via a read-only profile or simulate trades in paper mode.
agent/src/trading/connectors/dhan · high confidence
Introduce Futu (moomoo) trading connector with read-only and mandate-gated live profiles
Added a new connector for Futu (moomoo) that connects to a local OpenD gateway (default 127.0.0.1:11111) via the official futu-api SDK. The implementation provides four trading profiles: read-only paper and live accounts, plus paper trading and live trading profiles where live order placement is gated by a user mandate and requires unlocking the trade context with a hashed password. The connector enforces a strict paper-vs-live identity guard by matching the account's trd\_env (SIMULATE vs REAL) to the selected profile, ensuring live accounts cannot be driven under a paper profile. It exposes extended read capabilities (such as rehab, capital flow, and history deals) alongside standard account, position, order, quote, and historical bar queries, while keeping all write operations isolated behind the mandate gate.
agent/src/trading/connectors/futu · high confidence
Introduce Korea Investment & Securities (KIS) trading connector
Adds a new broker connector for Korea Investment & Securities (KIS), enabling access to Korean equities (KOSPI/KOSDAQ) via the official KIS Developers REST API. The connector supports genuine paper trading (모의투자) for both reading and placing orders, as well as read-only access to live accounts, leveraging KIS's structural separation of paper and live hosts to prevent accidental live trading. It includes built-in profiles, operation classification for safety gating, and configuration management for the new broker integration.
agent/src/trading/connectors/kis · high confidence
Introduce Longbridge trading connector with read-only access and secure credential handling
Added a new Longbridge (LongPort OpenAPI) trading connector that provides read-only access to account balances, positions, orders, executions, and market data via the official Python SDK. The implementation includes a dedicated credential resolution module that atomically loads App Key, App Secret, and Access Token from environment variables or a local runtime file, raising clear errors on conflicts or missing fields. To address the SDK's lack of a runtime discriminator between paper and live accounts, the connector enforces operator-declared profiles (paper-sdk, paper-trade, live-readonly) and marks all payloads with a config-trust guard, ensuring order placement is restricted to explicitly configured paper environments while live access remains read-only by default.
agent/src/trading/connectors/longbridge · high confidence
Introduce OKX trading connector with paper/live profiles and mandate-gated live trading
Added a new OKX trading connector that provides read-only access to account, market, and position data via the python-okx SDK, along with distinct profiles for paper (demo) and live environments. The connector supports paper trading with order placement capabilities and live trading where order placement is strictly gated behind a user-defined mandate and kill switch. Configuration is managed via a dedicated JSON file, and the connector includes built-in classification of SDK operations to enforce read/write separation for the live gate.
agent/src/trading/connectors/okx · high confidence
Introduce Robinhood connector with mandate enforcement and read-only portfolio mode
The Robinhood connector now includes a curated read/write classification map and an order-intent extractor that enforces mandate rules by parsing order parameters (symbol, side, notional/quantity, limit price) and denying ambiguous or missing data. It also adds a read-only portfolio profile that exposes account and position data without allowing trades, and fixes reply-shape parsing to correctly navigate nested JSON responses from the Robinhood MCP server.
agent/src/trading/connectors/robinhood · high confidence
Introduce Shadow Account for strategy extraction and backtesting
A new Shadow Account module has been added to the agent, enabling users to extract trading patterns from their broker journals and replay them as a 'shadow' strategy. The system parses trade journals to identify profitable roundtrips, uses machine learning to distill these into structured rules, and generates a re-runnable signal engine. Users can backtest these extracted strategies across multiple markets (China A-share, HK, US, Crypto) with multi-currency support, and receive detailed HTML/PDF reports featuring equity curves, attribution analysis, and today's potential signals.
_agent/src/shadow\account · high confidence
Introduce Strategy Development Manager with artifact store and decay monitoring
The Strategy Development Manager (SDM) is now available, providing a persistent store for research artifacts (factors and strategies) and automated decay monitoring. The store, backed by SQLite with an in-memory reference implementation, tracks artifact lifecycles (from creation to disabled) and enforces governance rules, such as preventing adapted child strategies from inheriting parent attestations. It includes a decay evaluation engine that classifies health based on metrics like IC ratio, Information Ratio, and Sharpe, automatically transitioning artifacts to monitoring or disabled states when performance degrades. The system also supports description-driven adaptation, allowing new strategies to be derived from existing ones while maintaining a clear lineage and validation status.
_agent/src/strategy\store · high confidence
Introduce Tiger Brokers trading connector with paper and live profiles
Added a new connector for Tiger Brokers that integrates with the official TigerOpen Python SDK to provide read-only access to account, market, and order data, as well as order placement capabilities. The change introduces four built-in profiles: two read-only options (paper and live) and two trade-enabled options (paper sandbox and live with mandate gating). The implementation includes configuration management for RSA-signed authentication, strict account-type validation to prevent mixing paper and live accounts, and a classification map to enforce write-gating for live trading operations.
agent/src/trading/connectors/tiger · high confidence
Introduce Upbit broker connector for Korean crypto markets
Added a new trading connector for Upbit, Korea's largest KRW crypto exchange, enabling read-only access to live account data and locally simulated paper trading. The implementation uses Upbit's public REST API with JWT authentication, providing three built-in profiles: a read-only live profile, a paper profile for market data, and a paper-trade profile that simulates order placement against live ticker prices. The connector is structurally capped at paper for order execution to mitigate risk, as Upbit offers no sandbox environment or runtime paper/live discriminator.
agent/src/trading/connectors/upbit · high confidence
Introduce Vibe-Trading Desktop shell with secure backend lifecycle and credential storage
This change adds the initial Electron host for Vibe-Trading, providing a single-instance desktop shell that manages a local Python backend process. The shell enforces a strict security boundary by binding the backend to 127.0.0.1, generating a per-launch authentication secret, and injecting it only into the backend's environment. It includes a parent-death watchdog to ensure the backend is terminated if the Electron process dies unexpectedly, and implements encrypted credential storage using Electron's safeStorage, migrating existing plaintext secrets from .env files. The desktop UI is localized into English, Simplified Chinese, Japanese, Korean, and Arabic, and includes a loading screen with retry and log-opening actions. The entry also documents dormant, fail-closed primitives for a future signed updater, including artifact verification and recovery journaling, though the updater itself is not yet enabled.
desktop/electron · high confidence
Introduce WebSocket channel runtime and compatibility helpers
The agent now includes a new \channelsui\ module that provides the runtime infrastructure for WebSocket-based communication. This adds support for normalizing CLI app and MCP preset mentions, handling workspace scope validation and persistence, issuing short-lived one-time tokens for client authentication, and bridging transcript events. It also introduces HTTP utility functions for route normalization and URL validation, media decoding helpers for saving base64 data URLs, and stubs for unsupported features like fork-chat and audio transcription to ensure graceful error handling.
agent/src/channelsui, agent/src/utils · high confidence
Introduce bounded-autonomy live trading channel with mandate enforcement and kill switch
The agent now supports a new live trading channel that allows autonomous execution within a user-committed mandate, ring-fenced in a dedicated broker account. This feature introduces a pre-trade enforcement gate that validates orders against mandate constraints (universe, instrument, notional, exposure, leverage, daily count) and enforces a fail-closed policy. A filesystem-based kill switch (HALT sentinel) provides an out-of-band global or per-broker halt mechanism, independent of the agent loop. All live actions are recorded in an append-only, tamper-evident audit ledger with redacted sensitive data. The system includes crash-safe recovery for unresolved orders and positions, daily order counting with atomic persistence, and classification of remote MCP tools to ensure write operations are always gated.
agent/src/live · high confidence
Introduce bounded-autonomy mandate system for live trading
The live trading channel now enforces a user-defined safety boundary (mandate) that restricts agent actions via quantitative hard caps (order notional, daily trade count, leverage, and instrument whitelist) and a discovery universe (asset classes, market-cap/liquidity floors, and symbol denylists). The mandate is loaded read-only at boot and is immutable to the agent loop; it is written only through a dedicated consent-commit path that requires explicit user approval, ensuring the agent cannot self-authorize or bypass these limits. The system includes strict validation, fail-closed behavior for missing or malformed mandates, and support for multiple asset classes including equities, crypto, forex, and CFDs.
agent/src/live/mandate · high confidence
Introduce durable research hypothesis registry with CLI management
Users can now track and manage research hypotheses via a new local JSON-backed registry. The system provides a CLI interface with commands to list, show, and invalidate hypotheses, allowing users to filter by status and view detailed metadata including linked backtest run cards. The registry enforces data integrity by rejecting blank required fields (title and thesis) and supports environment-based path configuration for storage location.
agent/src/hypotheses · high confidence
Introduce evidence-gated strategy discovery with per-regime performance tracking
The agent now includes a new strategy discovery subsystem that provides a unified, read-only catalog of strategies from both the Alpha Zoo registry and the Strategy Development Manager (SDM) store. This system enforces an evidence-gated approach: performance metrics are computed exclusively from real backtest run artifacts via a new evidence harness, which calculates per-regime (bull, bear, structural) statistics such as returns, Sharpe ratios, and drawdowns. The facade ensures that strategies are only recommended when supported by adequate, non-stale evidence, automatically refusing recommendations for strategies with insufficient data, stale evidence (older than 180 days), or multi-position artifacts that invalidate standard breakeven calculations. A persistent SQLite store tracks this evidence, and the system includes guards to prevent the agent from advertising tools that are not fully registered.
_agent/src/strategy\discovery · high confidence
Introduce finance research goal runtime with lifecycle and evidence tracking
The agent now supports a structured finance research goal runtime. This adds a new goal module that defines data models for goals, criteria, claims, and evidence, along with a policy layer that rejects live-trading or execution objectives. A SQLite-backed store manages the goal lifecycle (active, paused, complete, etc.) and persists evidence records, while context helpers format goal status and progress into the agent's prompt to guide multi-turn research sessions.
agent/src/goal · high confidence
Introduce local and official MCP read-only Interactive Brokers connector
Adds a new read-only Interactive Brokers connector that supports connecting to a local TWS or IB Gateway session (paper and live) as well as the official IBKR MCP OAuth endpoint. Users can now view account summaries, positions, quotes, and historical bars without exposing credentials or enabling order placement, with built-in profiles for paper trading, local live read-only access, and official MCP read-only access.
agent/src/trading/connectors/ibkr · high confidence
Introduce local read-only portfolio connection management
Users can now manage local, read-only portfolio data sources directly from the frontend. The new Connection Center allows creating, testing, and deleting local connections (such as Robinhood read-only profiles) and securely storing credentials in the OS vault. The Portfolio Source Editor lets users select which connections feed the portfolio, enable or disable specific accounts, reorder them, and toggle cash inclusion. A compatibility badge indicates the verification level of each connector, and the system supports account selection for brokers like Robinhood that require it.
frontend/src/components/portfolio · high confidence
Introduce multi-channel IM adapter layer
The agent now supports connecting to external chat platforms (Telegram, Discord, Slack, Feishu, DingTalk, Matrix, Email, etc.) via a new plugin-based channel architecture. This adds a dedicated \agent/src/channels\ module that includes a \ChannelManager\ for coordinating enabled channels, an async \MessageBus\ for decoupled inbound/outbound message routing, and a \BaseChannel\ interface that specific platform adapters implement. Users can now interact with the agent through their preferred chat service, with built-in support for features like streaming responses, media handling, and sender authorization (allowlists/pairing codes).
agent/src/channels · high confidence
Introduce observational pre-trade advisory interface
Added a new advisory layer in the live agent that allows external risk services to provide observational assessments on proposed orders without blocking execution. The implementation includes a broker-agnostic interface, data models for context and verdicts, and an orchestrator that aggregates results using a worst-case severity logic. The system is designed to be fail-open (converting provider errors to a 'review unavailable' status) and is disabled by default, requiring the VIBE\_TRADING\_ENABLE\_ADVISORY environment variable to activate. A mock provider is also included to support testing of the advisory integration.
agent/src/live/advisory · high confidence
Introduce offline harness for deterministic post-run evaluation
A new offline evaluation harness has been added to the agent/evals module, enabling deterministic verification of completed agent runs without invoking an LLM, tools, or network clients. The harness reads persisted artifacts (req.json, state.json, trace.jsonl, grounding evidence, LLM usage, and run manifest) and validates them against versioned case definitions covering execution status, identity resolution, tool usage, evidence integrity, budget limits, and risk constraints. It provides a CLI runner that outputs a JSON report with PASS, FAIL, NOT\_EVALUABLE, or INVALID\_ARTIFACT verdicts per assertion, and aggregates results by scenario and assertion code for CI-friendly exit codes.
agent/evals · high confidence
Introduce parallel cash-flow analytics spine for irregular holdings
A new \src.entities\ package provides a dedicated path for analysing holdings that lack daily OHLCV bars, such as private equity funds and bonds. It introduces \CashFlowSeries\ to manage irregular, dated cash flows with strict sign conventions and currency enforcement, alongside typed models for \Entity\, \Instrument\, \Bond\, and \Fund\. A robust ingestion layer (\load\_cashflows\) handles diverse file formats and column aliases while refusing to guess ambiguous data. This spine is consumed by new \quantlib\ modules for private-markets fund maths (\fundmath\) and client money-weighted performance (\performance\), ensuring that non-bar assets are priced and analysed correctly without leaking into the standard bar-based backtest engine.
agent/src/quantlib · high confidence
Introduce persistent cross-session memory system with hierarchical organization and compression
The agent now includes a new persistent memory subsystem that stores cross-session memories as Markdown files, organized into category subdirectories (user, feedback, project, reference) to enable scoped searches. The system features a three-level compression pipeline (Raw → Daily → Digest) using TF-IDF sentence scoring to summarize older entries, and implements lifecycle management with importance decay, quality scoring, and garbage collection. It also provides full-text search via a SQLite FTS5 index and automatic semantic linking between related memories using BM25 similarity, with all components gated behind feature flags.
agent/src/memory · high confidence
Introduce persistent live-trading runtime with crash-safe state and autonomous execution
The \agent/src/live/runtime\ package introduces the core infrastructure for a persistent, autonomous live-trading runner. This includes a durable, crash-safe job store (\jobstore.py\) that quarantines corrupt state to prevent silent failures, and a liveness system (\liveness.py\) using atomic heartbeats to detect and reap stale runner processes. The runner loop (\runner.py\) orchestrates autonomous trading ticks by enforcing a strict fail-closed sequence: checking for halts, validating mandate expiry, performing position reconciliation (\reconcile.py\) to detect ambiguous broker states, and executing trades. A new preemptive flatten mechanism (\flatten.py\) allows for safe, atomic cancellation of resting orders and closing of positions upon a halt trigger, with all actions audited. The system also features a wall-clock scheduler (\scheduler.py\) and market-aware triggers (\triggers.py\) to manage execution cadence.
agent/src/live/runtime · high confidence
Introduce read-only multi-broker portfolio aggregation
Adds a new read-only portfolio aggregation service that consolidates holdings from multiple connected brokers into a single dashboard. The implementation includes a compatibility layer that classifies connectors by their payload support (native, contract-tested, or experimental), a configuration module for selecting and ordering sources, and a dedicated reader for importing extraETF portfolio exports. It also introduces isolated worker processes for Longbridge and OAuth reconnections to prevent connector issues from crashing the main service, alongside SQLite persistence for immutable portfolio snapshots and FX rates.
agent/src/portfolio · high confidence
Introduce scheduled research jobs with timezone-aware execution and pre-built playbooks
Users can now create, persist, and automatically execute research jobs on a schedule. The system supports both fixed-interval (milliseconds) and standard 5-field cron expressions, with cron evaluation correctly respecting IANA timezones and handling DST transitions. Five pre-configured research playbooks are included (A-share money flow, earnings season tracker, institutional holdings diff, portfolio checkup, and pre-market brief) to get started quickly. Jobs are durable, crash-safe, and include a confirmation proposal workflow for mutations, with verdicts persisted and surfaced in the job list.
_agent/src/scheduled\research · high confidence
Introduce turnover-aware optimizer and fix lookback window leakage
A new TurnoverAwareOptimizer is added to the portfolio optimization suite, allowing users to penalize portfolio turnover via an L1 penalty term while supporting per-asset and per-group exposure caps. Additionally, the base optimizer logic is corrected to strictly exclude the current decision bar's returns from the lookback window, preventing future information leakage when weights are applied at the open of the decision bar. The RiskParity optimizer is also updated to use a constrained optimization method that ensures long-only weights.
agent/backtest/optimizers · high confidence
Introduces a structured trading connector framework with read-only profiles and local plugin support
The trading subsystem now uses a profile-based architecture to manage broker connections, starting with built-in read-only profiles for Scalable Capital (via Agentic MCP) and Trading 212 (via public REST API). These profiles enforce strict read-only capabilities, ensuring that order placement is disabled for these specific integrations. The system also introduces a local plugin mechanism that allows users to install and discover custom read-only connector plugins, alongside a new credential store that securely manages secrets using the OS keyring. This change establishes the foundational registry and onboarding contracts for connecting to external trading data sources.
agent/src/trading · high confidence
Introduces pluggable OCR engine architecture with local and cloud backends
The OCR tool now supports a pluggable engine interface, allowing users to switch between local processing via RapidOCR and cloud-based vision models (any OpenAI-compatible provider) using the VIBE\_TRADING\_OCR\_ENGINE environment variable. The system automatically discovers third-party engines installed via pip entry points, defaults to the first available local engine in 'auto' mode to keep data on-device, and includes backward-compatibility aliases for deprecated engine names like 'qwen-vl'.
agent/src/tools/ocr · high confidence
Kakushadze 101 Formulaic Alphas factor zoo added
The \agent/src/factors/zoo/alpha101\ directory now contains 101 standalone Python modules implementing the Kakushadze (2015) formulaic alphas. Each module provides a \compute\ function that calculates its specific alpha signal on OHLCV data, with metadata (such as required columns, universe, and warmup bars) defined in \\_\_alpha\meta\\_\. The implementation includes a LICENSE.md file crediting the source paper and clarifying that the code is an original reproduction of the mathematical formulas.
agent/src/factors/zoo/alpha101 · high confidence
Launch of static Vibe-Trading wiki with traffic analytics
A new static wiki site (vibetrading.wiki) is introduced, providing documentation, tutorials, and an alpha-library section. The site includes a footer that displays aggregate traffic counts distinguishing between AI-agent and human visitors, alongside PyPI install statistics, powered by Cloudflare Pages Functions and a D1 database. It also features a GitHub star counter, dark/light theme support, and internationalization.
wiki · high confidence
Launch of the Vibe-Trading Wiki home page
A new static home page for the Vibe-Trading wiki has been added at wiki/home/index.html. This page introduces the product as an open-source finance research agent, providing users with an overview of core capabilities such as the Agent Harness, backtesting across multiple market types, and Swarm Teams. It includes a clear installation section with commands for PyPI, uv, and source builds, and guides users to key resources like the product docs, tutorials, alpha library, and research lab. The page also features a dark/light theme toggle and displays a GitHub star count.
wiki/home · high confidence
New Alpha Library landing page with zoo cards and CLI examples
A new landing page for the Alpha Library has been added to the wiki, introducing a dedicated section to browse and benchmark pre-built quantitative alphas. The page displays key statistics (total alphas, generation date) and presents four distinct 'zoos'—Qlib158, Kakushadze 101, GTJA191, and Academic Anomalies—as interactive cards linking to their respective content. It also provides immediate 'Get started' instructions with CLI commands for listing and benchmarking alphas, while enforcing strict Content Security Policy (CSP) by externalizing scripts and loading theme initialization from a separate file.
wiki/alpha-library · high confidence
New GTJA Alpha 191 factor zoo added
This change introduces the GTJA Alpha 191 factor zoo, containing 191 short-period alpha formulas ported from the 2014 Guotai Junan Securities research report. The directory includes the mathematical definitions re-expressed in the project's operator algebra, along with a LICENSE.md documenting provenance and specific implementation deviations (such as approximations for WMA, SMA, and REGRESI). The factors are designed for the Chinese A-share equity universe and comply with the repository's purity and look-ahead guards.
agent/src/factors/zoo/gtja191 · high confidence
New Positions Tab with interactive visualization and sector resolution
A new PositionsTab component has been added to the Run Detail view, allowing users to visualize portfolio positions over time via pie charts and treemaps, with support for switching between date snapshots. The component distinguishes long and short exposures, classifies assets by class, and offers a 'Resolve industries' button to fetch sector mapping from the backend for symbols that the frontend cannot automatically classify. To support this UI, shared layout components (RunCardStat, RunCardPanel) were extracted into RunCard.tsx to avoid circular imports, and comprehensive tests were added to verify chart rendering, axis bounds, and sector resolution behavior.
frontend/src/components/run · high confidence
New Research Lab wiki section with initial GTJA alpha analysis
A new Research Lab section has been added to the Vibe-Trading wiki, providing a dedicated space for long-form quantitative research, backtests, and post-mortems. The initial entry features a detailed analysis of the 191 GTJA short-horizon alphas, evaluating their performance on the CSI 300 index from 2018 to 2025. This page includes reproducible CLI commands, statistical findings on alpha survival rates, and theme breakdowns, establishing the lab as a resource for open, data-driven quant research.
wiki/research-lab · high confidence
New Vibe-Trading beginner tutorial in Chinese
A new Chinese-language beginner tutorial has been added to the wiki, providing an introduction to Vibe-Trading concepts such as factors, strategies, backtesting, multi-market data sources, broker connectors, and Shadow Accounts for non-finance readers. This content is accessible via the new tutorials index page, which also includes a dark/light theme toggle and links to other wiki sections.
wiki/tutorials · high confidence
New academic factor zoo with price-based proxies and missing-data handling
The academic factor zoo now includes a suite of canonical research-grade factors (MKT-RF, SMB, HML, RMW, CMA, Carhart momentum, 52-week-high, short-term reversal, Amihud illiquidity, return skewness, Frazzini-Pedersen BAB, and correlation-rewiring stability) implemented as price/volume proxies using only OHLCV inputs. Each factor is cross-sectionally z-scored for long-short ranking, with explicit disclosures that they approximate original fundamental-based definitions. The correlation-rewiring factor uses a causal rolling comparison of event vs. calm correlation matrices, and all factors enforce strict missing-data handling (e.g., fill\_method=None) to avoid silent forward-filling of gaps, ensuring NaN propagation when coverage is insufficient.
agent/src/factors/zoo/academic · high confidence
New agent skills and data-source documentation for A-share risk analysis, cross-market strategies, and alpha research
The agent now includes a suite of new skills in \agent/src/skills\ that guide the AI through complex financial workflows. The \ashare-pre-st-filter\ skill provides a structured framework for predicting A-share ST/\*ST risk using financial statements and regulatory penalties. The \alpha-zoo\ skill enables browsing and benchmarking prebuilt factor libraries (e.g., Kakushadze 101, GTJA 191) with strict anti-lookahead constraints. The \cross-market-strategy\ skill and its example engine allow for backtesting portfolios spanning A-shares, US/HK/Canada equities, crypto, and forex, handling volatility-adjusted weighting and market-specific parameters. Additionally, new skills for \akshare\ and \ccxt\ document free data sources, while \correlation-regime\ and \bottleneck-hunter\ offer specialized analysis for market regime detection and supply-chain bottleneck arbitrage.
agent/src/skills · high confidence
New backtest benchmarking, Binance USD-M reconciliation, and portfolio constraints
The backtest module now includes a dedicated benchmark resolution system that automatically selects and fetches reference data (e.g., SPY for US equities, XIC.TO for Canada) based on strategy codes, while strictly failing closed for local/offline runs to prevent unintended network fallbacks. A new Binance USD-M reconciliation layer has been added to compare local risk state against exchange snapshots, generating deterministic drift evidence and supporting tolerance calibration from recorded comparisons. Additionally, the engine now supports composable weight constraints—allowing users to define per-name caps/floors and group exposure limits in their configuration—which are applied to optimizer outputs to shape portfolio allocations without altering position logic.
agent/backtest · high confidence
New benchmarking and reporting scripts for alpha performance analysis
Added three new scripts in agent/scripts to support performance benchmarking and reporting: bench\_performance.py provides a development-only tool to benchmark factor operators and equity calculation paths; w4a\_run\_benches.py acts as a driver to run benchmarks across four zoo/universe combinations (gtja191/CSI300, alpha101/SP500, qlib158/CSI300, alpha101/BTC) and outputs summary JSON and HTML reports; w4a\_patch\_blog.py patches HTML blog posts with benchmark results, including theme survival tables and top/dead alpha cards. These scripts enable systematic evaluation of alpha strategy performance and automated report generation.
agent/scripts · high confidence
New chat UI components for live trading, research goals, and agent activity
The chat interface now includes several new components to support advanced agent capabilities. The LiveRuntimePanel and RunnerStatus components provide real-time status, broker connection health, and mandate controls for live trading. The MandateProposalCard allows users to review and commit to trading constraints, while the GoalPanel enables interactive research goals with criteria tracking. The ActivityLine component displays agent activity status with live reasoning whispers, and the ScheduledResearchProposalCard handles scheduled research tasks. The Composer component now supports file attachments and integrates with these new panels.
frontend/src/components/chat · high confidence
New contributor documentation and packaging infrastructure
The repository now includes an Agent Contributor Guide for AI-assisted contributions, a Code of Conduct, and an updated Contributing guide with a Developer Certificate of Origin (DCO) requirement. A MANIFEST.in file ensures that tests, environment examples, and documentation are correctly included in source distributions.
(repo-wide) · high confidence
New dedicated pages for Alpha Zoo, Correlation, Options Lab, Portfolio, Reports, Runtime, Scheduled tasks, and Settings
The application now includes a suite of new frontend pages that provide dedicated interfaces for key capabilities. The Alpha Zoo page allows users to browse, filter, and benchmark alpha strategies across different universes. A new Correlation page enables users to compute and visualize asset correlation matrices and regime timelines. The Options Lab page offers an interactive environment for building options strategies, viewing payoff diagrams, and analyzing Greeks. The Portfolio page provides a multi-account overview with source management and history tracking. The Reports page serves as a library for browsing and filtering backtest runs. The Runtime page displays a live status dashboard for brokers and mandates. The Scheduled page allows users to create and manage timezone-aware research schedules. Finally, the Settings page centralizes configuration for LLM providers, data sources, and API channels.
frontend/src/pages · high confidence
New eToro Public API connector with demo and live profiles
A new eToro connector is available, supporting both demo (paper) and live trading via the eToro Public API. It provides read-only access to account snapshots, positions, and instrument search, as well as write capabilities for placing and managing orders and copy-trading workflows. The connector uses a single API key pair for both environments, with profiles selecting the appropriate API paths, and includes structural safety checks such as rejecting copy trading on demo accounts and enforcing mandates for live risk-increasing actions.
agent/src/trading/connectors/etoro · high confidence
New fundamental data schema and HTTP throttling infrastructure
The backtest engine now supports fundamental data analysis through a new unified schema (\_fundamental\_schema.py) that maps SEC XBRL concepts to standard fields like revenue, cogs, and net income, including derived metrics such as ROE and accruals. To support the increased API load from these new data sources, a shared HTTP client (\_http.py) has been added to enforce per-host rate limiting and session reuse, preventing IP bans from providers like Eastmoney. Additionally, utility modules for symbol detection (\_symbol\_utils.py) and Chinese market adjustments (cn\_adjust.py) have been introduced to improve data accuracy for A-shares and ETFs.
agent/backtest/loaders · high confidence
New governance primitives for tamper-evident audit logging and run methodology fingerprinting
The agent now includes a new governance module providing two core capabilities: a hash-chained, fsynced, append-only JSONL ledger for compliance-grade audit trails, and a content-addressed run manifest system that fingerprints the methodology (system prompt hash, injected skills, tool registry, and key package versions) into a deterministic hash. The ledger ensures tamper-evidence by chaining record hashes and enforcing durability via fsyncs and cross-platform file locking, while the manifest allows users to verify exactly which components and versions were used in any given run, enabling precise diffs between runs to detect methodology changes without exposing sensitive raw content.
agent/src/governance · high confidence
New institutional research slash commands
The CLI now exposes six new slash commands for institutional research workflows: /comps (comparable company analysis), /dcf (discounted cash flow valuation), /attrib (Brinson-Fachler performance attribution), /memo (investment memo), /earnings (earnings surprise bridge), and /screen (systematic idea screen). These commands provide structured, step-by-step execution skeletons with worked numeric examples and explicit missing-data policies, ensuring that the agent uses specific financial tools (such as get\_financial\_statements and screen\_market) and clearly reports any gaps in retrieved data rather than filling them from memory.
agent/cli/commands/institutional · high confidence
New interactive CLI UI with banner, rail dashboard, and transcript rendering
The interactive CLI now includes a new visual interface module (agent/cli/ui) that renders a startup banner with a gradient logo, a 'rail' dashboard to display agent activity steps (like shell commands, file reads, and searches) with status indicators, and a transcript renderer that converts Markdown pipe tables into formatted Rich tables while stripping horizontal rule separators for cleaner output.
agent/cli/ui · high confidence
New interactive research and attribution panels with specialized charting components
The frontend now includes a suite of new charting components in the charts directory to support advanced research and attribution features. Users can view Brinson attribution data through a detailed table, a cumulative performance line chart, and a waterfall chart breaking down allocation, selection, and interaction effects. A new Factor Research Panel displays IC series with moving averages and group equity performance, while a Correlation Matrix visualizes asset relationships via a color-coded heatmap. Additional specialized charts include a Monte Carlo fan chart for statistical validation, a Distribution chart for simulation samples, a Monthly Returns heatmap, and an Options Lab section featuring payoff diagrams and scenario matrices. These components are integrated into the Run Detail and Studio dashboards to provide deeper analytical insights.
frontend/src/components/charts · high confidence
New local development workflow script
A new \scripts/dev\ bash script has been added to streamline the local development environment. It provides commands to start, stop, restart, and check the status of the backend and frontend dev servers, automatically managing process IDs, logging, and health checks. This simplifies the setup for developers by handling environment variables and service dependencies in one place.
scripts · high confidence
New per-market data source priority and model picker controls in Settings
The Settings page now includes a new Data Source Priority card that lets users reorder the fallback data sources for each market (such as A-shares, US equities, crypto, and forex) and save the changes, which are applied immediately without a restart. It also introduces a Model Picker component for selecting or typing custom LLM models, featuring keyboard navigation, support for long provider/model slugs, and proper accessibility attributes. Additionally, a QVeris Settings section is added to manage the paid data marketplace integration, including API key configuration and budget credits.
frontend/src/components/settings · high confidence
New provider infrastructure and reliability hardening
The agent now includes a new provider capability registry (capabilities.py) and a content-filter resilience module (content\_filter.py) that allows the agent to tolerate content-filtered LLM responses by skipping blocked items instead of failing. A new OpenAI Codex OAuth provider (openai\_codex.py) enables ChatGPT-based coding via OAuth, while a GitHub Copilot SDK adapter (copilot\_auth.py) provides an alternative coding path. The LLM factory (llm.py) has been expanded to support OpenAI Responses API mapping, proxy-free HTTP clients, and OpenCode session headers. Additionally, the chat module (chat.py) now captures reasoning content, usage metadata, and content filter triggers, and normalizes finish reasons to improve ReAct loop stability.
agent/src/providers · high confidence
New research and analytics tools for alpha strategies, portfolio performance, and A-share market signals
This update introduces a suite of new agent tools in the \agent/src/tools\ directory. The Alpha Zoo framework adds \alpha\_zoo\ (browse registry), \alpha\_bench\ (run backtests and generate HTML reports with integrity-protected caching), and \alpha\_compare\ (head-to-head ranking of alphas). Portfolio analytics are expanded with \cashflow\_performance\ for time-weighted, Modified Dietz, and money-weighted returns on accounts with irregular cash flows. A-share market intelligence is enhanced with \block\_trades\ (Eastmoney block trade data) and \dragon\_tiger\ (Eastmoney dragon-tiger board disclosures). Additionally, \etf\_holdings\ provides read-only look-through of US (SEC N-PORT) and A-share ETF holdings, and \autopilot\ scaffolds research goals from hypotheses. Supporting infrastructure includes \\_result\_paging\ to prevent truncated JSON responses and \\_shell\_safety\ to block broad Python process termination commands.
agent/src/tools · high confidence
New run-scoped grounding gate for numeric evidence and identity
The agent now enforces a structural grounding gate that validates numeric claims against actual tool results before release. This new package introduces run-scoped identity locking (ensuring market data consumers use symbols locked before the current tool batch), evidence intake (mapping tool field names to canonical price/metric kinds), and a figures block contract (where the model declares the role of each number—observed, derived, proposed, cited, or count—which is then verified against the evidence ledger). The system prevents unverified figures from streaming to the user, handles corrections for mismatched values or missing evidence, and redacts unrecoverable claims while preserving table structure.
agent/src/agent/grounding · high confidence
Options Lab panel with payoff diagram, spot-IV scenarios, Greeks and live chain
The WebUI now includes an Options Lab section that lets users build and analyze options strategies. Users can construct multi-leg strategies using a StrategyBuilder with preset templates, view real-time market data in an OptionsChainTable (showing strikes, bid/ask, volume, open interest, and implied volatility), and see risk metrics displayed in GreeksCards (Delta, Gamma, Theta, Vega, Rho) with color-coded tones. The interface is fully internationalized and supports dark mode, with local font loading for Inter and JetBrains Mono to ensure consistent rendering.
frontend · high confidence
Port of qlib158 Alpha158 factor zoo
Added the qlib158 factor zoo, a clean-room re-expression of Microsoft's Alpha158 feature set. This update introduces 154 alpha factors—including Beta, Count (up/down/diff), Correlation (price-volume), and Position (max/min)—across 5, 10, 20, 30, and 60-day windows. The implementation is adapted from the upstream \qlib\ project (pinned to commit \d5379c5\) and is available for US, Chinese, Hong Kong, Indian, and Korean equity markets.
agent/src/factors/zoo/qlib158 · high confidence
Shadow Account report and signal engine templates
Added the HTML and CSS templates for the Shadow Account research report, which displays a cover with delta PnL, shadow profile details, backtest metrics, and a detailed attribution section that explicitly discloses roundtrips excluded due to currency mismatches. Also added the Jinja2 template for the auto-generated signal engine, which implements conditional entry logic (including an entry-hour gate that is now correctly skipped for daily bars to prevent false rejections) and computes RSI and prior returns for rule matching.
_agent/src/shadow\account/templates · high confidence
Swarm workers now receive real-time market data grounding
Swarm workers are now pre-fed recent OHLCV market data for symbols mentioned in user prompts, preventing reliance on outdated training data. The new \grounding.py\ module scans user variables for stock tickers (e.g., \NVDA.US\, \700.HK\) and bare US tickers, fetching the last 30 days of price data via the existing loader registry. This data is rendered as a markdown block and injected into the worker's system prompt via \build\_worker\_prompt\. The system also includes security hardening across the swarm module: \models.py\ now enforces strict redaction of credentials and internal paths in public metadata, \store.py\ validates run IDs to prevent path traversal, and \runtime.py\ secures artifact re-homing during run resumption to prevent file system escape.
agent/src/swarm · high confidence
Unified cross-market backtest engine with per-market rule enforcement
The backtest engine has been refactored into a composite architecture that supports multiple asset classes (equities, futures, forex, crypto) within a single run. A new \CompositeEngine\ manages a shared capital pool and routes symbols to specialized sub-engines (e.g., \ChinaAEngine\, \ChinaFuturesEngine\, \CryptoEngine\) based on a centralized symbol classification system in \\_market\_hooks.py\. This ensures that market-specific rules—such as T+1 settlement for A-shares, margin requirements for futures, and funding/liquidation logic for crypto—are applied correctly. The change also introduces strict currency validation to prevent mixing settlement currencies in a single backtest.
agent/backtest/engines · high confidence
Windows desktop packaging and lifecycle safety
The Windows desktop build pipeline now includes hardened packaging and lifecycle controls. The backend build script (build-backend.ps1) pins Python 3.12.10 and GTK 3.24.31 with SHA-256 verification, installs Python dependencies from a hash-locked requirements file, and cleans stale packaging artifacts safely. Electron runtime preparation (prepare-electron.mjs) downloads the official Electron archive with checksum verification and bounded retries. Packaging scripts enforce security gates: the unsigned review installer (build-review-installer.mjs) builds without code signing and verifies that artifacts remain unsigned, while the signed installer (build-signed-installer.mjs) requires Authenticode credentials, forces code signing, and verifies the signature before publishing. Lifecycle safety is improved with a process-sentinel helper, bounded process execution (process-utils.ps1), and smoke tests that verify the backend lifecycle, parent-death cleanup, and update-safety boundaries (including update-recovery.js and update-verification.js).
desktop/electron/scripts · high confidence
Architecture
API server refactored into modular route packages
The monolithic \\api\_server.py\\ has been split into focused, modular route packages (e.g., \\alpha\_routes\\, \\attribution\_routes\\, \\auth\_routes\\, \\channels\_routes\\, \\connection\_routes\\, \\live\_routes\\, \\options\_routes\\) under \\agent/src/api\\. This structural change improves maintainability and testability by isolating specific feature areas into their own modules, while introducing a shared compatibility layer (\\\_compat.py\\) to handle dependency resolution and monkeypatching across the extracted modules.
agent/src/api · high confidence
CLI refactoring and expanded configuration surface
The CLI entry point has been refactored into a modular package structure, extracting pure formatting helpers (duration, tokens, number abbreviation) and thinking-verb utilities into new \\agent/cli/utils\\ modules, while the monolithic \\agent/cli.py\\ has been removed. The API server has been restructured into a thin assembler that imports extracted security, model, and helper modules from \\src.api\\. Additionally, the \\.env.example\\ file has been significantly expanded to document support for 11+ LLM providers (including OpenRouter, Anthropic, OpenAI Codex, GitHub Copilot, MiniMax, and others) and detailed data source configurations, reflecting the platform's broadened provider and market coverage.
agent · high confidence
CLI restructured into a modular package with legacy compatibility
The single-file CLI has been refactored into a structured \\agent/cli\\ package, separating the interactive REPL (\\main\\, \\input\\, \\completer\\) and UI components (\\components\\) from the legacy non-interactive subcommands (\\serve\\, \\run\\, \\mcp\\, \\swarm\\) preserved in \\\_legacy.py\\. This change introduces a new versioning system that derives the version from \\pyproject.toml\\ or package metadata, and adds a compatibility layer that re-exports legacy symbols to ensure existing tests and downstream callers continue to work without modification.
agent/cli · high confidence
Behavioural changes
CI safety gates enforce centralized config access and timezone standards
New CI gates in the tools directory enforce stricter coding standards: raw environment variable reads (os.getenv, os.environ.get, os.environ\[...\]) are now blocked outside the centralized config layer, deprecated datetime.utcnow() calls are rejected in favor of timezone-aware UTC timestamps, unsafe yaml.load() usage is prohibited, and process-wide os module patches in tests are confined to the module under test to prevent teardown failures.
tools · high confidence
Enhanced theme persistence and robust SSE connection management
The frontend now persists the dark/light theme preference to local storage and synchronizes it across browser tabs and system preference changes, ensuring a consistent user experience. Additionally, the Server-Sent Events (SSE) hook has been refactored to handle authentication tickets for secure connections, ignore stale connections during retries, and support a wider range of event types including new swarm, goal, and live trading signals, improving reliability and feature coverage.
frontend/src/hooks · high confidence
Frontend library overhaul: new security, i18n, and domain logic modules
The \frontend/src/lib\ directory has been significantly restructured with the addition of several new modules and the removal of the legacy \i18n.tsx\ provider. Security is hardened via \apiAuth.ts\ (which exchanges API keys for single-use SSE tickets to keep secrets out of URLs) and \escapeHtml.ts\ (which prevents XSS in ECharts tooltips). Internationalization is modernized through \swarmI18n.ts\ and updated formatters in \formatters.ts\ (supporting Chinese labels), while domain logic is expanded with \options.ts\ (Options Lab types), \positions.ts\ (portfolio parsing), \tearsheet.ts\ (equity/drawdown calculations), \cadence.ts\ (schedule parsing), and \swarmStatus.ts\ (agent state normalization). The \api.ts\ module now includes comprehensive types for portfolio snapshots and correlation regimes, and \echarts.ts\ adds support for heatmap, pie, and treemap charts.
frontend/src/lib · high confidence
Improved session reliability with streaming checkpoints, crash recovery, and robust error handling
Sessions now persist assistant responses incrementally during streaming via durable checkpoints, ensuring that partial replies are recovered and displayed if the service restarts mid-generation. The session service enforces a strict one-run-per-session rule to prevent message interleaving and introduces a global full-text search index for cross-session history lookup. Additionally, the system now tolerates corrupt session and message files without aborting, uses timezone-aware UTC timestamps for consistency, and provides explicit terminal state events (completed, cancelled, failed) to improve UI feedback.
agent/src/session · high confidence
Layout overhaul: expanded navigation, improved accessibility, and robust connection handling
The main layout component now features a significantly expanded sidebar with new navigation entries for Runtime, Scheduled, Reports, Portfolio, Alpha Zoo, Options Lab, Settings, and Correlation, all fully localized via react-i18next. Accessibility has been improved with ARIA labels, skip-to-content links, and proper icon hiding. The ConnectionBanner has been refactored to only display during active reconnection attempts (hiding the initial disconnected state), includes a manual reload button for persistent disconnections, and uses semantic ARIA roles. Sidebar collapse state is now persisted using a shared storage utility that supports cross-tab synchronization, and session lists automatically refresh on external title updates.
frontend/src/components/layout · high confidence
Security scanner and token neutralization for external content
The agent now includes a security module that scans external tool outputs (web, search, document) for prompt-injection patterns and neutralizes chat-template control tokens. The scanner adds warning metadata to JSON envelopes when it detects instructions attempting to override system rules, exfiltrate secrets, or impersonate privileged roles, allowing downstream agents to treat such content as untrusted. Additionally, the system defangs special tokenizer markers (such as ChatML, DeepSeek, Llama, and Gemma delimiters) by inserting zero-width spaces, preventing external text from forging role boundaries while remaining visually identical. This change also introduces workspace access and network validation helpers to ensure tool outputs respect scope and URL constraints.
agent/src/security · high confidence
Startup preflight checks and improved market-data routing
The agent now runs startup preflight checks to verify LLM provider connectivity (including OpenAI Codex OAuth and GitHub Copilot SDK) and data source availability, blocking startup if the LLM is unreachable. Market data routing has been expanded to support UK/Irish equities (.L/.IL), Canadian TSX/TSXV (.TO/.V), Korea (KRX), India (NSE/BSE), and Yahoo futures/forex/index suffixes, with automatic fallback between sibling venues (e.g., .TO ↔ .V) and shared FX canonicalization to prevent symbol mismatches. The run detail UI now supports opt-in chart payloads, reconstructs charts through the loader registry, and skips non-positive moving-average periods to avoid rendering errors.
agent/src · high confidence
Visual identity refresh and dark mode support
The application's visual identity has been updated with a new logo and favicon featuring an orange-to-yellow gradient and a bar-chart icon, replacing the previous blue network-node design. The brand name has also changed to "Vibe-Trading". Additionally, a new theme-boot script has been added to automatically apply a dark or light theme based on user preference or system settings, ensuring consistent styling across the interface.
frontend/public · high confidence
Web UI overhaul with route-level lazy loading and new pages
The frontend application has been restructured to significantly improve initial load performance and expand feature coverage. Route-level lazy loading has been implemented for all major pages (Home, Agent, RunDetail, Compare, Settings, Runtime, Scheduled, Reports, Portfolio, Correlation, OptionsLab, AlphaZoo), reducing the initial bundle size and introducing a loading state during navigation. The router has been updated to include several new pages: Settings, Runtime, Scheduled, Reports, Portfolio, Correlation, OptionsLab, and AlphaZoo (with sub-routes for bench, compare, and individual alpha IDs). The Home page is now accessible at /about, and the default route (/) now loads the Agent page. Additionally, the UI has been enhanced with a new dark mode surface system for better contrast, RTL layout support, streaming animations, and improved accessibility features like reduced-motion support.
frontend/src · high confidence
Fixes
Improved run state persistence and sandbox subprocess hardening
The run state store now uses fsync when writing state files to prevent data corruption on crashes, and adds support for marking runs as cancelled. The runner introduces sandbox hardening for backtest subprocesses: it restricts virtual memory and file descriptors via a post-exec bootstrap (fixing crashes on multi-threaded servers), and isolates the HOME directory to expose only specific loader paths (cache, data-bridge, qveris.json), mitigating unauthorized access to sensitive user data.
agent/src/core · high confidence
Test coverage
Add comprehensive test coverage for the QuantLib valuation module; Added comprehensive test coverage for the Tier 2 memory subsystem; Added frontend test infrastructure and test helpers; Added frontend test suite for chat components; Added i18n locale parity and utility tests; Added memory retrieval benchmark suite with quality gates; Added test coverage for common UI components; Added test coverage for useDarkMode and useSSE hooks; Added test infrastructure and golden data for factor analysis; Added tests for Agent, Portfolio, and Run Detail page behaviors; Added tests for Attribution, Factor Research, and Strategy Research dashboard components; Added tests for Vite proxy configuration; Added tests for agent store and streaming DOM stability; Added tests for layout components; Added tests for the offline Harness artifact verifier; Added tests for the positions sectors API endpoint; Added unit and integration tests for the OpenBB Workspace agent bridge; Comprehensive test coverage for quantlib financial-mathematics primitives; Frontend test suite for core library modules; Test infrastructure for the agent module.
Dependencies
New desktop build infrastructure and channel SDK support
The project now includes a dedicated Electron-based desktop build configuration (desktop/electron/package.json) and a separate requirements file for channel integrations (agent/requirements-channels.txt). The desktop build introduces Electron 43.1.1 and associated tooling, establishing a new packaging target for the application. Simultaneously, the channel SDK dependencies (lark-oapi, qrcode, python-telegram-bot) are now explicitly managed in a dedicated lock file to ensure reproducible, hash-pinned installs for these specific integrations, distinct from the main agent runtime.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 58.
Lenses
- Code Health 69
- Architecture 98
- Maturity 60
- Readiness 48
- Security 83
- Accessibility 67
Changes since last survey
- 300 commits — 142 feature/other, 158 fixes
By area
- agent/src — 109 commits
- (repo) — 105 commits
- (root) — 31 commits
- agent/backtest — 26 commits
- agent/tests — 20 commits
- frontend/src — 5 commits
- .github/workflows — 2 commits
- agent/.env.example — 1 commit
- desktop/electron — 1 commit
Notable commits
- fix: Merge #1349 into #1341 and fix the two defects the combination exposes
- fix: Merge pull request #1261 from Emad211/fix/windows-cross-platform
- fix: Merge pull request #1265 from aminak58/fix/grounding-joined-crypto
- fix: Merge pull request #1269 from AirHua-byte/codex/fix-grounding-resolution-context
- fix: Merge pull request #1280 from aminak58/fix/fx-metals-futures-routing
- fix: Merge pull request #1338 from cgycorey/fix/1336-block-unsupported-claims
- fix: Merge pull request #1341 from saju01/fix/tool-dedup-argument-aware
- fix: Merge pull request #1344 from cgycorey/fix/1274-rebalance-commission-scale
- fix: Merge pull request #1345 from cgycorey/fix/1343-worker-preset-tools
- fix: Merge pull request #1346 from saju01/fix/grounding-percentage-point-mask
- fix: Merge pull request #1347 from ethanstoner/fix/strategy-store-tie-ordering
- fix: Merge pull request #1348 from Shizoqua/fix/codex-response-model-metadata
- fix: Merge pull request #1349 from HKUDS/fix/microcompact-dedup-ledger
- fix: Merge pull request #1351 from cgycorey/fix/us-dotted-class-share-tickers
- fix: Merge pull request #1352 from cgycorey/fix/loop-compaction-tool-call-arguments
- fix: Merge pull request #1356 from he-yufeng/fix/journal-dividend-cashflow
- fix: Merge pull request #1358 from saju01/fix/compaction-call-identity
- fix: Merge pull request #1359 from birdxs/fix/docker-build-upgrade-action-version
- fix: Merge pull request #1361 from cgycorey/fix/mcp-buy-limit-notional-worse-of
- fix: Merge pull request #1362 from cgycorey/fix/report-audit-zero-verified-fail-closed
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
HKUDS/Vibe-Trading was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 18 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e5f719567a0a8c943c08276b0295b95c572891fb — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-5d04157a340d.