Skip to content

[External Plugin]: TraderSpy #4786

Description

@muratkaragozgil

Plugin name

traderspy

Short description

Read-only crypto futures market research in Copilot CLI: AI-generated signals, smart-money positions across Binance, Hyperliquid, Bybit and OKX, 19 technical indicators, funding and open interest, a market screener and a backtester, with six playbook skills. No order, transfer or withdrawal tool. Market data and analysis, not financial advice.

GitHub repository

target1m/traderspy-mcp

Plugin path inside the repository

No response

Ref to review

v1.10.0

Commit SHA to review

36635b72e9c2b50611e9bf802044ee1812d5a193

Version

1.10.0

License identifier

MIT

Author name

TraderSpy

Author URL

https://traderspy.app

Homepage URL

https://traderspy.app/mcp

Keywords

crypto, market-data, technical-analysis, smart-money, ai-signals, screener, backtesting, read-only, mcp

Additional notes for reviewers

This is the official TraderSpy plugin, maintained by T1M LLC (https://target1m.io). It bundles six skills (market-briefing, market-screener, position-check, smart-money, technical-analysis, trading-signals) and one hosted Streamable HTTP MCP server, https://mcp.traderspy.app/mcp.

Strictly read-only market research. The server has 17 tools, each annotated readOnlyHint: true. There is no order, transfer, withdrawal or account tool: it cannot place, close or modify an order, and it cannot see anyone's exchange account. Every skill tells the assistant to report what the data shows and leave decisions to the user. Market data and analysis, not financial advice.

Access: Copilot CLI signs in with a TraderSpy account through OAuth (dynamic client registration, PKCE, scope mcp.read). No key or secret is stored in the repository. A free account allows 300 tool calls a day; initialize and tools/list answer without an account.

Manifest: the Copilot CLI manifest is .github/plugin/plugin.json (Copilot CLI's legacy format, with the server declared inline). The repository also ships Claude Code, Cursor, Grok Build and Gemini CLI manifests, and its root mcp.json belongs to the Cursor plugin, which sends a personal key. That is why this plugin does not use an Agent Plugins root plugin.json, and the spec-compliance gate will report warnings.

Install directly with copilot plugin install target1m/traderspy-mcp. The server is also listed in the Official MCP Registry as app.traderspy/traderspy (version 3.0.2). Documentation: https://github.com/target1m/traderspy-mcp#readme. Privacy policy: https://traderspy.app/privacy-policy. Contact: support@traderspy.app.

Submission checklist

  • The plugin lives in a public GitHub repository.
  • The ref and/or sha I provided is immutable (release tag and/or full 40-character commit SHA), not a branch.
  • This submission follows this repository's contribution, security, and responsible AI policies.
  • This plugin is not already listed in the Awesome Copilot marketplace.

Activity

  1. github-actions commented on Oct 9, 2026

    @github-actions
    Contributor

    🟡 Contributor Reputation Check: MEDIUM risk

    Check Risk
    Profile MEDIUM
    Credential audit NONE

    Maintainers: please review this contributor before merging.
    See the workflow run for full details.
    Automated check powered by AGT.

  2. added
    needs-review:MEDIUMContributor reputation check flagged MEDIUM risk
    external-pluginPublic external plugin submission
    ready-for-reviewSubmission passed intake validation and is ready for maintainer review
    on Oct 9, 2026
  3. github-actions commented on Oct 9, 2026

    @github-actions
    Contributor

    ⚠️ External plugin intake passed with spec warnings

    This submission passed blocking quality checks and is ready for maintainer review, but it has non-blocking Agent Plugins spec compliance warnings.

    View workflow run · Download full quality gate logs

    Reviewer signals

    These are non-blocking heuristics for maintainer review; they are not evidence of misconduct or low quality.

    Signal Result
    Repository age 211 day(s)
    Repository activity 0 stars; 0 watchers; 0 forks
    Repository counts 0 stars · 0 watchers · 0 forks · 0 open issues/PRs
    Homepage heuristics ⚠️ pricing

    Quality gate summary

    Legend: ✅ pass · ⚠️ warning · 🛑 fail

    Gate Status
    spec compliance (non-blocking) ⚠️ warning
    vally lint ✅ pass
    install smoke test ✅ pass
    version match ✅ pass
    ref/sha consistency ✅ pass
    canvas structure ⚪ not_run
    • spec compliance: warning
    • vally lint: pass
    • install smoke test: pass
    • version match: pass
    • ref/sha consistency: pass
    • canvas structure: not_run
    • overall: pass
    spec compliance output (⚠️ warning)
    Agent Plugins v1.0.0 manifest warnings:
    - manifest location is ".github/plugin/plugin.json"; expected "plugin.json" at plugin root
    - $schema should be "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json"
    - top-level field "mcpServers" is not part of Agent Plugins v1.0.0
    - schema validation: manifest must have required property '$schema'
    - schema validation: manifest must NOT have additional properties
    
    vally lint output (✅ pass)
    ✅ market-briefing (2/2 checks passed)
        ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
            ✓ spec-compliance: All spec checks passed.
        ✓ [valid-refs] All file references across 1 skill(s) are valid.
            ✓ valid-refs: All file references resolve to existing files within the skill directory.
    ✅ market-screener (2/2 checks passed)
        ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
            ✓ spec-compliance: All spec checks passed.
        ✓ [valid-refs] All file references across 1 skill(s) are valid.
            ✓ valid-refs: All file references resolve to existing files within the skill directory.
    ✅ position-check (2/2 checks passed)
        ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
            ✓ spec-compliance: All spec checks passed.
        ✓ [valid-refs] All file references across 1 skill(s) are valid.
            ✓ valid-refs: All file references resolve to existing files within the skill directory.
    ✅ smart-money (2/2 checks passed)
        ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
            ✓ spec-compliance: All spec checks passed.
        ✓ [valid-refs] All file references across 1 skill(s) are valid.
            ✓ valid-refs: All file references resolve to existing files within the skill directory.
    ✅ technical-analysis (2/2 checks passed)
        ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
            ✓ spec-compliance: All spec checks passed.
        ✓ [valid-refs] All file references across 1 skill(s) are valid.
            ✓ valid-refs: All file references resolve to existing files within the skill directory.
    ✅ trading-signals (2/2 checks passed)
        ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
            ✓ spec-compliance: All spec checks passed.
        ✓ [valid-refs] All file references across 1 skill(s) are valid.
            ✓ valid-refs: All file references resolve to existing files within the skill directory.
    
    6 skill(s) linted, 6 passed
    
    install smoke test output (✅ pass)
    Install smoke test succeeded. Verified /tmp/external-plugin-quality-ypvB8e/copilot-home/.copilot/installed-plugins/external-plugin-intake/traderspy/.github/plugin/plugin.json.
    
    Version match output
    - v1.10.0: matched version "1.10.0" at ".github/plugin/plugin.json".
    - 36635b72e9c2b50611e9bf802044ee1812d5a193: matched version "1.10.0" at ".github/plugin/plugin.json".
    
    Ref/SHA consistency output
    source.ref "v1.10.0" resolves to the same commit as source.sha "36635b72e9c2b50611e9bf802044ee1812d5a193".
    
    Canvas structure output
    Canvas structure gate skipped because plugin is not tagged with "canvas".
    

    Canonical external.json payload

    {
      "name": "traderspy",
      "description": "Read-only crypto futures market research in Copilot CLI: AI-generated signals, smart-money positions across Binance, Hyperliquid, Bybit and OKX, 19 technical indicators, funding and open interest, a market screener and a backtester, with six playbook skills. No order, transfer or withdrawal tool. Market data and analysis, not financial advice.",
      "version": "1.10.0",
      "author": {
        "name": "TraderSpy",
        "url": "https://traderspy.app"
      },
      "repository": "https://github.com/target1m/traderspy-mcp",
      "homepage": "https://traderspy.app/mcp",
      "license": "MIT",
      "keywords": [
        "crypto",
        "market-data",
        "technical-analysis",
        "smart-money",
        "ai-signals",
        "screener",
        "backtesting",
        "read-only",
        "mcp"
      ],
      "source": {
        "source": "github",
        "repo": "target1m/traderspy-mcp",
        "ref": "v1.10.0",
        "sha": "36635b72e9c2b50611e9bf802044ee1812d5a193"
      }
    }
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    external-pluginPublic external plugin submissionneeds-review:MEDIUMContributor reputation check flagged MEDIUM riskready-for-reviewSubmission passed intake validation and is ready for maintainer review

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions