ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      fxm1618-gmail

      Safety Report

      LongPort Quant Trader (房总版)

      @fxm1618-gmail

      长桥证券量化交易集成 - 自动超跌/动量策略 + 飞书推送 + 绩效跟踪。支持港股/美股自动交易,每 5 分钟监控,止盈止损管理。适用于想要自动化交易的个人投资者和量化爱好者。

      114Downloads
      0Installs
      0Stars
      1Versions

      Security Analysis

      high confidence
      Clean0.08 risk

      The skill's requirements, install steps, and runtime instructions match a LongPort-connected automated trading bot — the requested API keys and python runtime are proportional to its stated purpose.

      Mar 23, 202655 files2 concerns
      Purpose & Capabilityok

      Name/description (LongPort quantitative trader) align with required binaries (python3), required env vars (LONGPORT_APP_KEY, LONGPORT_APP_SECRET, LONGPORT_ACCESS_TOKEN), and the included Python code which calls longport.openapi for market data and order submission.

      Instruction Scopenote

      The SKILL.md instructs typical setup steps (pip install longport, set env vars, run quant_monitor.py). Runtime code legitimately reads env vars, queries quotes, and submits orders. Note: multiple scripts persist state to /tmp (e.g., /tmp/auto_trade_state.json, /tmp/auto_trade_performance.json) and write logs (logs/quant_monitor.log) — expected for a trading bot but worth being aware of because these files hold trading state and should be protected.

      Install Mechanismnote

      Install spec only ensures python3 via Homebrew ([email protected]) which is reasonable. The README/SKILL.md also instructs pip installing third-party packages (longport, python-dotenv) but that pip install is not encoded in the install spec — it's a normal omission but means the environment must run pip to install dependencies before use.

      Credentialsok

      Only LongPort API credentials are required (LONGPORT_APP_KEY, LONGPORT_APP_SECRET, LONGPORT_ACCESS_TOKEN), which are directly relevant. Optional Feishu webhook config is documented but not required. No unrelated tokens or high-privilege credentials are requested.

      Persistence & Privilegeok

      Skill is not always-enabled and uses normal agent invocation. It stores state and performance data to local files under /tmp and logs; it does not request or modify other skills or system-level configurations. This persistence is typical for a trading bot.

      Guidance

      This skill is coherent for automated trading, but granting it your LongPort API credentials permits live order submission — treat them like real-money keys. Before using in production: 1) Test thoroughly on the provider's sandbox/simulated account (use a sandbox access token if available). 2) Review and run the code in an isolated environment (dedicated machine/container) to protect keys and state files. 3) Keep secrets out of source control (.env and shell rc files), rotate keys if exposed, and consider creating a LongPort token/account scoped to limited permissions if the platform supports it. 4) Be aware the bot persists state and logs (/tmp and logs/...), so secure or clean those files if needed. 5) If you don't trust the publisher, inspect all scripts (especially those that send data externally) before providing credentials.

      Latest Release

      v1.0.0

      longport-quant-trader v1.0.0 – Initial Release - 自动化港股/美股超跌抄底与动量追涨策略 - 集成飞书推送,实时通知与绩效报告 - 内置止盈止损机制,自动仓位管理 - 提供交易绩效跟踪与定时市场扫描(每5分钟) - 支持通过命令启动监控、查持仓、配置参数、生成报告

      Popular Skills

      self-improving-agent

      @pskoett · 1,456 stars

      Gog

      @steipete · 672 stars

      Tavily Web Search

      @arun-8687 · 620 stars

      Find Skills

      @JimLiuxinghai · 529 stars

      Proactive Agent

      @halthelobster · 426 stars

      Summarize

      @summarize · 415 stars

      Published by @fxm1618-gmail on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]