Skip to content
Back to skills

Canary Harness

ASecurity

Use the repo-local Canary MCP/CLI for Interactive Brokers account, market, Edge performance review, rulebook, stress, proposal, opportunity, and order investigations while developing the trading harness. Read/preview first; explicit current-turn broker writes use only the gated CLI.

  • 8 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 19, 2026
ai-agentsgoperformance

Works with

  • cli
  • mcp

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add osauer/canary --skill canary-harness --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Canary Harness?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Canary Harness
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/osauer-canary-harness/badge)](https://www.skillsdirectory.com/skills/osauer-canary-harness)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: canary-harness
description: Use the repo-local Canary MCP/CLI for Interactive Brokers account, market, Edge performance review, rulebook, stress, proposal, opportunity, and order investigations while developing the trading harness. Read/preview first; explicit current-turn broker writes use only the gated CLI.
---

Updated: 2026-09-05

## Contract

Use the typed `canary` MCP tools for read-only brief, detailed regime and portfolio stress, Edge review, account, positions,
rulebook, named-symbol technical, proposal, opportunity, settings, trading,
health, and order-status/history work. Use `canary ... --json` when MCP is
unavailable, a CLI-only policy/reconciliation diagnostic is required, or the
project needs an exact reproducible CLI artifact.

The MCP surface cannot place, modify, cancel, exercise, liquidate, or
transmit. An explicit current-turn broker-write request uses only the
agent-origin gated CLI; trading readiness, route/account/client pins, preview
tokens, broker WhatIf/eligibility, freeze state, journaling, and daemon
authorization remain binding. A minted preview token is not submit authority.
Settings/freeze changes, policy/reconciliation governance writes, and
destructive daemon maintenance remain human-only.

Preserve typed evidence exactly: nil is unavailable rather than zero; report
live/delayed/frozen data, freshness, stale reasons, session context, source
health, and warning details when material. Local order history is intent and
lifecycle evidence, not an IBKR statement or complete broker audit.

## Canonical References

This is only the repo-development safety overlay. Detailed command selection,
schemas, and domain authority stay in:

- [command catalog](../../../skills/canary/SKILL.md)
- [Rulebook design and authority](../../../internal-docs/design/trading-rulebook.md)

## Project Workflow

Read the root AGENTS.md before editing. For daemon/CLI/MCP/trading semantic
changes, use `.agents/docs/daemon-cli-trading-contract.md`. For Canary SPA
changes, use `.agents/docs/spa-authority-matrix.md`.

After daemon or CLI edits, run the required tests and smoke tier, refresh the
installed daemon, and capture redacted `canary status --json` plus one command
that exercises the change. Report every skip and first failure explicitly.

Files in this skill

  • SKILL.md2.2 KB
  • agents/openai.yaml481 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…