Contributions are welcome when they preserve the CLI's local/read-only scope.
- Do not add live order, modification, close, cancellation, withdrawal, broker login, or credential storage commands.
- Use synthetic fixtures and paper/sandbox mode only.
- Keep runtime dependencies empty unless a reviewed requirement cannot be met safely with the standard library.
- Never put secrets in arguments, URLs, logs, fixtures, snapshots, or errors.
- Keep remote access GET-only and HTTPS-only.
- Add negative tests for each security boundary you touch.
PYTHONPATH=src python -m compileall -q src tests
PYTHONPATH=src python -m unittest discover -s tests -vKeep user-facing output concise and JSON output stable. By contributing, you agree that your contribution is licensed under Apache-2.0 and that you have the right to submit it.