SQXtreme — StrategyQuant X MCP control layer
Wrapper/extension over sq-mcp that adds Windows-first DX, Spanish localization, and multi-client configs for AI agents (opencode, Claude Code, Cursor, VS Code).
Repo: https://github.com/herjarsa/sqxtreme-mcp
What ships in v0.4.3
sq-mcp (DAVIDAROCA27) is the foundation: 482 runtime tools, MIT, 1571 tests. SQXtreme v0.4.3 adds (126 tests, 1 skipped; CI verde ubuntu+windows × py3.10–3.12; OIDC publish):
- Windows installer —
iwr install.ps1 | iex(4 modos: CheckOnly/PyPI/FromSource/FromGit) - Spanish localization — 5 workflow prompts + 4 sub-agentes (
prompts/es/) - Multi-client configs — Claude Code, opencode, Cursor, VS Code (
examples/) - HTTP transport —
SQXTREME_TRANSPORT=http→streamable-httpen:8765(vs nativo:8082) - 12 features 3 fases — AlgoWizard auto-import, Builder desde frase, Live Watch, Streaming, Data auto-fix, Auto-curator, Ship MT5, Snapshot rollback, Ashare 119, Scheduled Runner, sqx-tools wrapper, Health Dashboard
- Visual QA + Orchestrator (v0.4.2) —
qa_dashboard(metrics),orchestrate(workspaces) - Audit fixes (v0.4.3) — 26 fixes aplicados: TOCTOU race fix, path traversal hardening, injection guard regex, version sync via
importlib.metadata, mypyLiteraltype narrowing, 4 new tests files, 29 nuevos tests. VerCHANGELOG.mdpara detalle completo. - CI matrix — Ubuntu + Windows × Python 3.10/3.11/3.12 — ruff + mypy + pytest
- PyPI OIDC — Trusted Publishing sin token manual (
publish.yml)
Roadmap (post v0.4.3)
Migración a mcp>=2.0 cuando sea estable (actualmente pin <2 por FastMCP→MCPServer rename).
Install
# One-liner (after PyPI publish)
iwr https://raw.githubusercontent.com/herjarsa/sqxtreme-mcp/main/install.ps1 -UseBasicParsing | iex
# Or from source
git clone https://github.com/herjarsa/sqxtreme-mcp.git
cd sqxtreme-mcp
.\scripts\install.ps1 -FromSource
What this gets you (honest scope)
Running an AI agent with SQXtreme + [full] extra: 9 Spanish MCP prompts + 482 sq-mcp runtime tools delegated + cross-client install + 26 audit fixes de seguridad.
NOT included in v0.4.3: a live AI agent actually connected (manual client setup per docs/CLIENTS.md), E2E test with real SQ X engine.
Security
v0.4.3 incluye auditoria completa de seguridad:
- 5 fixes Critical (path traversal, CWD fallback, TOCTOU race, file corruption, Unix-only test)
- 10 fixes Important (injection guard regex, version drift, KeyError, stdout pollution, etc.)
- Full report:
AUDIT_REPORT.md(902 lines)
License
MIT.
Release files for sqxtreme-mcp 0.4.3
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sqxtreme_mcp-0.4.3.tar.gz | 49.3 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sqxtreme_mcp-0.4.3-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 75.5 kB
Release files / sqxtreme_mcp-0.4.3.tar.gz
| Download URL | sqxtreme_mcp-0.4.3.tar.gz |
|---|---|
| Size | 49.3 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
461f3d06f7dbda228e3d278d8254de1a68fceaca11f50eeb0e8906e92256f66a
|
|
BLAKE2b-256 checksum How to use checksums |
c6fab1553925be99f7cfa061d9253e4ac9ea9a9e8e110bd128daa34239d92064
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.
Transparency logRelease files / sqxtreme_mcp-0.4.3-py3-none-any.whl
| Download URL | sqxtreme_mcp-0.4.3-py3-none-any.whl |
|---|---|
| Size | 26.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
ba6d37b0adb01c94006c929fccce05f757ce1837d8a784280709102b2f3101ac
|
|
BLAKE2b-256 checksum How to use checksums |
6f9acdd72a8cd06f16da4ce8262061e6bcfa0b10ebe1c35ab1d9f56c0b081d3a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 31, 2026.
Transparency log