Skip to main content

SQXtreme — StrategyQuant X MCP control layer

Wrapper/extension over sq-mcp that adds Windows-first DX, Spanish localization, and multi-client configs for AI agents (opencode, Claude Code, Cursor, VS Code).

Repo: https://github.com/herjarsa/sqxtreme-mcp

What ships in v0.4.3

sq-mcp (DAVIDAROCA27) is the foundation: 482 runtime tools, MIT, 1571 tests. SQXtreme v0.4.3 adds (126 tests, 1 skipped; CI verde ubuntu+windows × py3.10–3.12; OIDC publish):

  1. Windows installer — iwr install.ps1 | iex (4 modos: CheckOnly/PyPI/FromSource/FromGit)
  2. Spanish localization — 5 workflow prompts + 4 sub-agentes (prompts/es/)
  3. Multi-client configs — Claude Code, opencode, Cursor, VS Code (examples/)
  4. HTTP transport — SQXTREME_TRANSPORT=http → streamable-http en :8765 (vs nativo :8082)
  5. 12 features 3 fases — AlgoWizard auto-import, Builder desde frase, Live Watch, Streaming, Data auto-fix, Auto-curator, Ship MT5, Snapshot rollback, Ashare 119, Scheduled Runner, sqx-tools wrapper, Health Dashboard
  6. Visual QA + Orchestrator (v0.4.2) — qa_dashboard(metrics), orchestrate(workspaces)
  7. Audit fixes (v0.4.3) — 26 fixes aplicados: TOCTOU race fix, path traversal hardening, injection guard regex, version sync via importlib.metadata, mypy Literal type narrowing, 4 new tests files, 29 nuevos tests. Ver CHANGELOG.md para detalle completo.
  8. CI matrix — Ubuntu + Windows × Python 3.10/3.11/3.12 — ruff + mypy + pytest
  9. PyPI OIDC — Trusted Publishing sin token manual (publish.yml)

Roadmap (post v0.4.3)

Migración a mcp>=2.0 cuando sea estable (actualmente pin <2 por FastMCP→MCPServer rename).

Install

# One-liner (after PyPI publish)
iwr https://raw.githubusercontent.com/herjarsa/sqxtreme-mcp/main/install.ps1 -UseBasicParsing | iex

# Or from source
git clone https://github.com/herjarsa/sqxtreme-mcp.git
cd sqxtreme-mcp
.\scripts\install.ps1 -FromSource

What this gets you (honest scope)

Running an AI agent with SQXtreme + [full] extra: 9 Spanish MCP prompts + 482 sq-mcp runtime tools delegated + cross-client install + 26 audit fixes de seguridad.

NOT included in v0.4.3: a live AI agent actually connected (manual client setup per docs/CLIENTS.md), E2E test with real SQ X engine.

Security

v0.4.3 incluye auditoria completa de seguridad:

  • 5 fixes Critical (path traversal, CWD fallback, TOCTOU race, file corruption, Unix-only test)
  • 10 fixes Important (injection guard regex, version drift, KeyError, stdout pollution, etc.)
  • Full report: AUDIT_REPORT.md (902 lines)

License

MIT.

Release files for sqxtreme-mcp 0.4.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sqxtreme-mcp 0.4.3
File Size Uploaded
sqxtreme_mcp-0.4.3.tar.gz 49.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sqxtreme-mcp 0.4.3
File Interpreter ABI Platform
sqxtreme_mcp-0.4.3-py3-none-any.whl Python 3 none any Details

Total release size: 75.5 kB

Release files / sqxtreme_mcp-0.4.3.tar.gz

Download URL sqxtreme_mcp-0.4.3.tar.gz
Size 49.3 kB
Tags Source
SHA-256 checksum
How to use checksums
461f3d06f7dbda228e3d278d8254de1a68fceaca11f50eeb0e8906e92256f66a
BLAKE2b-256 checksum
How to use checksums
c6fab1553925be99f7cfa061d9253e4ac9ea9a9e8e110bd128daa34239d92064
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release files / sqxtreme_mcp-0.4.3-py3-none-any.whl

Download URL sqxtreme_mcp-0.4.3-py3-none-any.whl
Size 26.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ba6d37b0adb01c94006c929fccce05f757ce1837d8a784280709102b2f3101ac
BLAKE2b-256 checksum
How to use checksums
6f9acdd72a8cd06f16da4ce8262061e6bcfa0b10ebe1c35ab1d9f56c0b081d3a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.

Transparency log

Release history Release notifications | RSS feed

0.8.2

2 release files

0.8.1

2 release files

0.8.0

2 release files

0.7.0

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

This release

0.4.3 This release

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.0

1 release file

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page