SkillAgentSearch skills...

extensions

This is the raw dev repo for "QuanuX" (Quant-Linux). Official releases are available via @QuanuX org. Quantitative Framework for Research, Development and Deployment of Proprietary Trading Strategies. Website under development.

Install / Use

npx skills add quantDIY/QuanuX --skill extensions

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

69/100

Category

Security

Supported Platforms

Universal

Our assessment of extensions

extensions scores 69/100 on our quality scale, 1066th of 1,122 Security skills we index.

Its SKILL.md is 4.1 KB long, well organised into 12 sections with 3 code examples: a solid amount of guidance for an agent.

It has no GitHub stars yet, so there is no community track record; judge it on its content.

Substance
26/30
Structure
18/20
Description
15/15
Adoption
0/20
Freshness
11/15

Maintenance, license and trust

  • The repository was last updated about 6 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.
  • Our last check on 2026-09-26 found the source still online.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 78/100, with 2 cautions from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.

AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

extensions compared with similar skills

All 4 of these similar skills score higher than extensions; compare them before choosing.

SkillScoreStarsUpdatedFormat
extensions (this skill)by quantDIY6906mo agoSKILL.md
algorithmic-artby anthropics100177.9k15d agoSKILL.md
pptxby anthropics100177.9k15d agoSKILL.md
designby nextlevelbuilder100133.6k4d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100133.6k4d agoSKILL.md

Frequently asked questions

How do I install extensions?
Run npx skills add quantDIY/QuanuX --skill extensions. The install tabs above show the steps for each supported agent.
Which AI agents does extensions work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is extensions safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It declares no license and scores 78/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is extensions still maintained?
The repository was last updated about 6 months ago. That is recent enough to be usable, but agent tooling moves fast, so check the instructions against your agent's current version.

name: quanux-extension-standards description: The authoritative "School of Architecture" for building QuanuX Extensions (Sidecars). Enforces the QXP protocol, Go runtime preference, and privacy-first security model. metadata: version: 1.0.0 author: QuanuX priority: 10

QuanuX Extension Standards (QXP)

"Bolt-on, don't Build-in."

This skill defines the architecture for extending QuanuX. We prefer Sidecar Processes over monolithic plugin systems. This ensures isolation, stability, and polyglot capability, though Go is the standard.

1. The "Sidecar" Philosophy

An extension is a standalone binary that runs alongside the Core Server.

  • Isolation: If the extension crashes, Core survives.
  • Performance: Extensions perform heavy lifting (websocket streaming, encoding) outside the Python GIL.
  • Privacy: Extensions run locally. No data leaves the machine unless the extension explicitly does so (and the user configured it).

2. Directory Structure

All extensions reside in the root /extensions directory.

/extensions
  /my-extension
    /cmd          # (Optional) if complex
    main.go       # Entrypoint (Go)
    extension.yaml # Manifest
    README.md

3. The Manifest (extension.yaml)

Every extension MUST have a manifest.

name: "sierra-chart-bridge"
display_name: "Sierra Chart Connector"
version: "0.0.1"
runtime: "go" # or "node", "python" (Go preferred)
command: "./dist/sierra-bridge" # Relative to extension dir
  - "market.data.read"
  - "strategy.execute"
env:
  - "QUANUX_BRIDGE_KEY" # Injected by quanuxctl
upstream_repo: "https://github.com/my/repo.git" # (Optional) Enable Package Management

4. Package Management (Lifecycle)

Extensions can opt-in to managed upgrades by defining upstream_repo in extension.yaml.

  • Versioning: quanuxctl will query git ls-remote --tags on the upstream repo.
  • Build Script: quanuxctl passes QUANUX_EXT_VERSION environment variable to build.sh.
    • Your build.sh MUST prioritize this variable over hardcoded versions.
    • Example: VERSION=${QUANUX_EXT_VERSION:-"v1.0.0"}.
  • Commands: This enables quanuxctl upgrade, upgradeable, and install -v.

5. Communication Protocol

Inbound (Core -> Extension)

  • Extensions SHOULD expose an HTTP or gRPC server.
  • They LISTEN on a configurable port (default range 9000-9100).

Outbound (Extension -> Core)

  • Extensions connect to QuanuX Core via WebSocket or HTTP.
  • Auth: Use QUANUX_BRIDGE_KEY (injected via ENV) to authenticate with Core.

5. Security & Secrets

  • NO Hardcoded Creds: Never store API keys in code.
  • Keyring: Use the System Keyring via quanuxctl or server/security/secrets.py.
  • Injection: Secrets are injected as Environment Variables at runtime.

6. Implementation Guide (Go)

New extensions should use the standard Go layout:

package main

import (
    "net/http"
    "os"
    "log"
)

func main() {
    // 1. Read Config (Env Vars)
    bridgeKey := os.Getenv("QUANUX_BRIDGE_KEY")
    if bridgeKey == "" {
        log.Fatal("QUANUX_BRIDGE_KEY required")
    }

    // 2. Setup Server
    mux := http.NewServeMux()
    mux.HandleFunc("/health", healthHandler)

    // 3. Start
    port := os.Getenv("PORT")
    if port == "" { port = "9000" }
    log.Fatal(http.ListenAndServe(":"+port, mux))
}

## 7. Remote Connectivity & Port Forwarding

**Protocol**: Extensions MUST support remote deployments where the Target App (e.g. Sierra Chart) is on a different machine than QuanuX Core.

-   **Configurable Host/Port**:
    -   NEVER hardcode `localhost`.
    -   ALWAYS accept `QUANUX_<NAME>_HOST` and `QUANUX_<NAME>_PORT`.
-   **Tunneling Support**:
    -   This design explicitly supports **SSH Tunneling** (e.g. `ssh -R`) and **Reverse Proxies**.
    -   Example: QuanuX (Cloud) -> Connects to `localhost:11099` (Tunneled) -> User PC (Sierra Chart).
    -   Extensions must handle connection drops gracefully (reconnect logic) to support tunnel restarts.

8. Specialized Extensions

Related Skills

View on GitHub
GitHub Stars0
CategorySecurity
Updated5mo ago
Forks0

Trust signals

78/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 medium1 low1 info
extensions — Universal Skill: Install & Safety Check | SkillAgent