by Travisun
Opptrix — AI驱动的全球多市场投研工作台 | Open-source LLM research assistant for China A-shares. 170+ MCP tools, factor screening, backtest, watchlist & Electron desktop. TypeScript · React · Fastify monorepo.
# Add to your Claude Code skills
git clone https://github.com/Travisun/OpptrixLast scanned: 7/13/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@electron/rebuild: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@fastify/static: @fastify/static vulnerable to path traversal in directory listing",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "app-builder-lib: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "cacache: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "dmg-builder: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "electron: Electron: AppleScript injection in app.moveToApplicationsFolder on macOS",
"severity": "high"
},
{
"type": "npm-audit",
"message": "electron-builder: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "electron-builder-squirrel-windows: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "form-data: form-data uses unsafe random function in form-data for choosing boundary",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "glob: glob CLI: Command injection via -c/--cmd executes matches with shell:true",
"severity": "high"
},
{
"type": "npm-audit",
"message": "jimp: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "jpeg-js: Infinite loop in jpeg-js",
"severity": "high"
},
{
"type": "npm-audit",
"message": "make-fetch-happen: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimist: Prototype Pollution in minimist",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "mkdirp: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "node-gyp: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "request: Server-Side Request Forgery in Request",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "resize-img: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tar: node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "to-ico: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "tough-cookie: tough-cookie Prototype Pollution vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "url-regex: Regular expression denial of service in url-regex",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"file": ".cursor/skills/codegraph/SKILL.md",
"line": 55,
"type": "remote-install",
"message": "Install command (remote install script piped to a shell — review the source before running): \"curl -fsSL https://raw.githubusercontent.com/colbymchenry/codegraph/main/install\"",
"severity": "medium"
}
],
"status": "FAILED",
"scannedAt": "2026-07-13T06:52:03.308Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how Opptrix compares with popular alternatives.
Opptrix is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by Travisun. Opptrix — AI驱动的全球多市场投研工作台 | Open-source LLM research assistant for China A-shares. 170+ MCP tools, factor screening, backtest, watchlist & Electron desktop. TypeScript · React · Fastify monorepo. It has 274 GitHub stars.
Opptrix failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/Travisun/Opptrix" and add it to your Claude Code skills directory (see the Installation section above).
Opptrix is primarily written in TypeScript. It is open-source under Travisun on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh Opptrix against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
[!IMPORTANT] 特别提醒:Opptrix 投研工作台正在全面重构,当前处于开发版本,各项功能尚不稳定、也不完善,请审慎采用。
| 能力 | 说明 |
|---|---|
| Chat Agent | 流式对话;按意图自动挂载投研工具包(150+) |
| 工作流技能 | 170+ 内置技能(量化 / 价值投资 / Lean / 核心投研)+ 个人技能导入 |
| 全球多市场 | CN · US · HK · JP · KR — 搜索、行情、K 线、筛选、跨市场分析 |
| 新闻 · 行情动态 · 右侧面板 | 订阅阅读、市场情绪、关注列表、发现策略、计划任务 |
| 网页交付 / 子 Agent | 可预览投研页;复杂任务派生子任务 |
| 能力 | 说明 |
|---|---|
| .opx 扩展 | 打包 → 验签 → 安装 → 激活 → 卸载全生命周期;独立宿主子进程 + vm 沙盒隔离 |
| 能力网关 | storage / events / data / schedule / llm(thin) / shell(thin) 等 token 化能力;权限先行、fail-closed |
| 贡献点 | 只读 Hook(会话消息/工具前置)、HTTP 子路由 /api/ext/{id}/*、计划任务 |
| 商店(本地就绪) | Registry 协议 + 客户端全链验签(Ed25519);UI 入口下一版本开放 |
| 通道 | 流式 |
|---|---|
| Telegram / Slack / Feishu | ✅ 阶段编辑 + 终稿编辑(与 Web 聊天体验一致) |
| 钉钉 / 企业微信 / QQ | ✅ 终稿应答(平台限制) |
主路径:自托管。 数据与会话留在你自己的机器或服务器。
npm i -g @opptrix/selfhost
opptrix init
opptrix up # 优先 pull 预构建镜像 → https://127.0.0.1:8712
opptrix doctor
Linux 从零:
curl -fsSL https://raw.githubusercontent.com/Travisun/Opptrix/main/scripts/bootstrap/linux.sh | bash
export PATH="$HOME/.local/bin:$PATH"
opptrix up
对话需自备 LLM API Key。版本升级 / 回退 / 常用命令见 docs/SELF-HOSTING.md。
| 文档 | 说明 |
|---|---|
| docs/SELF-HOSTING.md | 自托管部署、升级、回退、1GB 内存画像 |
| docs/ARCHITECTURE.md | 分层、数据流、持久化(精读版) |
| docs/ARCHITECTURE-COMPREHENSIVE.md | 全面架构指南 |
| docs/MAINTENANCE.md | 维护手册:模块地图、常见任务、测试与发布、审计清单 |
| docs/API.md | REST / Hub features / 平台与扩展端点 |
| docs/EXTENSION-PLATFORM-ARCHITECTURE.md | 扩展平台架构(Phase A/B) |
| docs/EXTENSION-STORE-PROTOCOL.md | 扩展商店 Registry 协议 v1.0 |
| docs/EXTENSION-PLATFORM-ADR-02-AMENDMENT.md | 隔离模型决策(共享宿主 + 多层补偿) |
| docs/AGENT-GUIDE.md | AI 协作者手册 |
| docs/DATA-LAYER.md | 数据层 / Provider 演进 |
| docs/UI-DESIGN-SYSTEM.md · docs/UI-LAYOUT.md | 设计系统与布局规范 |
产品化开发者文档(双语,逐步充实)见仓库同级 opptrixdocuments/ 目录。
请在使用前仔细阅读。使用本软件即表示你已理解并同意以下条款。
| 说明 | 内容 |
|---|---|
| 产品性质 | Opptrix 是 数据查询与投研信息整理工具,用于聚合公开/授权数据源、辅助阅读与检索。不是 证券投顾软件、不是 券商交易终端、不提供 代客理财、不支持 自动下单或实盘交易。 |
| 非投资建议 | 软件内展示的行情、财务、新闻、因子、策略信号、机构观点摘要及一切 AI 生成内容,均仅供学习、研究与信息整理,不构成 任何形式的投资建议、要约、邀约或承诺。 |
| AI 内容风险 | 大模型可能产生错误、遗漏或「幻觉」;请 以工具返回的结构化数据为准,勿单独依据自然语言结论做决策。 |
| 数据局限性 | 行情可能延迟、缺失或错误;多数据源回退 不保证 实时性与准确性;第三方接口受各自服务条款与限流约束。 |
| 策略与回测 | 因子筛选、回测、信号验证基于历史数据,过往表现不代表未来收益。 |
| 责任归属 | 你基于本软件所作的任何投资或交易决定及由此产生的一切后果,由你自行承担;开发者与贡献者不对因使用本软件导致的任何直接或间接损失负责。 |
| 合规 | 请遵守所在国家/地区的证券、数据与隐私相关法规;接入 Tushare、LLM 等服务须自行配置凭证并遵守其协议。 |
界面截图、示例对话与演示数据 不代表 真实荐股或实盘推荐,请勿作为实际投资依据。
扫码加入 QQ 用户群,使用问题、功能建议与同路人交流更方便:
Opptrix 坚持免费、开源。赞助不是购买,而是对理念的认可——你的支持会帮助我们把 Opptrix 发展得更加强大。
感谢每一位支持者(与 官网赞助墙 同步):
向本仓库提交贡献即视为同意 CLA(English)与 CONTRIBUTING。
main 建分支