Repository navigation
[External Plugin]: TraderSpy #4786
Copy link
Copy link
Open
Labels
external-pluginPublic external plugin submissionPublic external plugin submissionneeds-review:MEDIUMContributor reputation check flagged MEDIUM riskContributor reputation check flagged MEDIUM riskready-for-reviewSubmission passed intake validation and is ready for maintainer reviewSubmission passed intake validation and is ready for maintainer review
Description
Activity
🟡 Contributor Reputation Check: MEDIUM risk
Check Risk Profile MEDIUM Credential audit NONE Maintainers: please review this contributor before merging.
See the workflow run for full details.
Automated check powered by AGT.- addedneeds-review:MEDIUMContributor reputation check flagged MEDIUM riskContributor reputation check flagged MEDIUM riskexternal-pluginPublic external plugin submissionPublic external plugin submissionready-for-reviewSubmission passed intake validation and is ready for maintainer reviewSubmission passed intake validation and is ready for maintainer review
on Oct 9, 2026 ⚠️ External plugin intake passed with spec warningsThis submission passed blocking quality checks and is ready for maintainer review, but it has non-blocking Agent Plugins spec compliance warnings.
View workflow run · Download full quality gate logs
- Plugin: traderspy
- Repository: https://github.com/target1m/traderspy-mcp
- Ref:
v1.10.0 - SHA:
36635b72e9c2b50611e9bf802044ee1812d5a193
Reviewer signals
These are non-blocking heuristics for maintainer review; they are not evidence of misconduct or low quality.
Signal Result Repository age 211 day(s) Repository activity 0 stars; 0 watchers; 0 forks Repository counts 0 stars · 0 watchers · 0 forks · 0 open issues/PRs Homepage heuristics ⚠️ pricingQuality gate summary
Legend: ✅ pass ·
⚠️ warning · 🛑 failGate Status spec compliance (non-blocking) ⚠️ warningvally lint ✅ pass install smoke test ✅ pass version match ✅ pass ref/sha consistency ✅ pass canvas structure ⚪ not_run - spec compliance: warning
- vally lint: pass
- install smoke test: pass
- version match: pass
- ref/sha consistency: pass
- canvas structure: not_run
- overall: pass
spec compliance output (
⚠️ warning)Agent Plugins v1.0.0 manifest warnings: - manifest location is ".github/plugin/plugin.json"; expected "plugin.json" at plugin root - $schema should be "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json" - top-level field "mcpServers" is not part of Agent Plugins v1.0.0 - schema validation: manifest must have required property '$schema' - schema validation: manifest must NOT have additional propertiesvally lint output (✅ pass)
✅ market-briefing (2/2 checks passed) ✓ [spec-compliance] All 1 skill(s) are spec-compliant. ✓ spec-compliance: All spec checks passed. ✓ [valid-refs] All file references across 1 skill(s) are valid. ✓ valid-refs: All file references resolve to existing files within the skill directory. ✅ market-screener (2/2 checks passed) ✓ [spec-compliance] All 1 skill(s) are spec-compliant. ✓ spec-compliance: All spec checks passed. ✓ [valid-refs] All file references across 1 skill(s) are valid. ✓ valid-refs: All file references resolve to existing files within the skill directory. ✅ position-check (2/2 checks passed) ✓ [spec-compliance] All 1 skill(s) are spec-compliant. ✓ spec-compliance: All spec checks passed. ✓ [valid-refs] All file references across 1 skill(s) are valid. ✓ valid-refs: All file references resolve to existing files within the skill directory. ✅ smart-money (2/2 checks passed) ✓ [spec-compliance] All 1 skill(s) are spec-compliant. ✓ spec-compliance: All spec checks passed. ✓ [valid-refs] All file references across 1 skill(s) are valid. ✓ valid-refs: All file references resolve to existing files within the skill directory. ✅ technical-analysis (2/2 checks passed) ✓ [spec-compliance] All 1 skill(s) are spec-compliant. ✓ spec-compliance: All spec checks passed. ✓ [valid-refs] All file references across 1 skill(s) are valid. ✓ valid-refs: All file references resolve to existing files within the skill directory. ✅ trading-signals (2/2 checks passed) ✓ [spec-compliance] All 1 skill(s) are spec-compliant. ✓ spec-compliance: All spec checks passed. ✓ [valid-refs] All file references across 1 skill(s) are valid. ✓ valid-refs: All file references resolve to existing files within the skill directory. 6 skill(s) linted, 6 passedinstall smoke test output (✅ pass)
Install smoke test succeeded. Verified /tmp/external-plugin-quality-ypvB8e/copilot-home/.copilot/installed-plugins/external-plugin-intake/traderspy/.github/plugin/plugin.json.Version match output
- v1.10.0: matched version "1.10.0" at ".github/plugin/plugin.json". - 36635b72e9c2b50611e9bf802044ee1812d5a193: matched version "1.10.0" at ".github/plugin/plugin.json".Ref/SHA consistency output
source.ref "v1.10.0" resolves to the same commit as source.sha "36635b72e9c2b50611e9bf802044ee1812d5a193".Canvas structure output
Canvas structure gate skipped because plugin is not tagged with "canvas".Canonical external.json payload
{ "name": "traderspy", "description": "Read-only crypto futures market research in Copilot CLI: AI-generated signals, smart-money positions across Binance, Hyperliquid, Bybit and OKX, 19 technical indicators, funding and open interest, a market screener and a backtester, with six playbook skills. No order, transfer or withdrawal tool. Market data and analysis, not financial advice.", "version": "1.10.0", "author": { "name": "TraderSpy", "url": "https://traderspy.app" }, "repository": "https://github.com/target1m/traderspy-mcp", "homepage": "https://traderspy.app/mcp", "license": "MIT", "keywords": [ "crypto", "market-data", "technical-analysis", "smart-money", "ai-signals", "screener", "backtesting", "read-only", "mcp" ], "source": { "source": "github", "repo": "target1m/traderspy-mcp", "ref": "v1.10.0", "sha": "36635b72e9c2b50611e9bf802044ee1812d5a193" } }
Metadata
Metadata
Assignees
Labels
external-pluginPublic external plugin submissionPublic external plugin submissionneeds-review:MEDIUMContributor reputation check flagged MEDIUM riskContributor reputation check flagged MEDIUM riskready-for-reviewSubmission passed intake validation and is ready for maintainer reviewSubmission passed intake validation and is ready for maintainer review
Plugin name
traderspy
Short description
Read-only crypto futures market research in Copilot CLI: AI-generated signals, smart-money positions across Binance, Hyperliquid, Bybit and OKX, 19 technical indicators, funding and open interest, a market screener and a backtester, with six playbook skills. No order, transfer or withdrawal tool. Market data and analysis, not financial advice.
GitHub repository
target1m/traderspy-mcp
Plugin path inside the repository
No response
Ref to review
v1.10.0
Commit SHA to review
36635b72e9c2b50611e9bf802044ee1812d5a193
Version
1.10.0
License identifier
MIT
Author name
TraderSpy
Author URL
https://traderspy.app
Homepage URL
https://traderspy.app/mcp
Keywords
crypto, market-data, technical-analysis, smart-money, ai-signals, screener, backtesting, read-only, mcp
Additional notes for reviewers
This is the official TraderSpy plugin, maintained by T1M LLC (https://target1m.io). It bundles six skills (market-briefing, market-screener, position-check, smart-money, technical-analysis, trading-signals) and one hosted Streamable HTTP MCP server, https://mcp.traderspy.app/mcp.
Strictly read-only market research. The server has 17 tools, each annotated
readOnlyHint: true. There is no order, transfer, withdrawal or account tool: it cannot place, close or modify an order, and it cannot see anyone's exchange account. Every skill tells the assistant to report what the data shows and leave decisions to the user. Market data and analysis, not financial advice.Access: Copilot CLI signs in with a TraderSpy account through OAuth (dynamic client registration, PKCE, scope
mcp.read). No key or secret is stored in the repository. A free account allows 300 tool calls a day;initializeandtools/listanswer without an account.Manifest: the Copilot CLI manifest is
.github/plugin/plugin.json(Copilot CLI's legacy format, with the server declared inline). The repository also ships Claude Code, Cursor, Grok Build and Gemini CLI manifests, and its rootmcp.jsonbelongs to the Cursor plugin, which sends a personal key. That is why this plugin does not use an Agent Plugins rootplugin.json, and the spec-compliance gate will report warnings.Install directly with
copilot plugin install target1m/traderspy-mcp. The server is also listed in the Official MCP Registry asapp.traderspy/traderspy(version 3.0.2). Documentation: https://github.com/target1m/traderspy-mcp#readme. Privacy policy: https://traderspy.app/privacy-policy. Contact: support@traderspy.app.Submission checklist