Skip to content

About

Local-first multi-agent market research desktop workspace built with Tauri, Next.js, and an embedded TradingAgents-compatible core.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

30 stars

Watchers

1 watching

Forks

Latest commit

 

History

36 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Evidence Loom logo

Evidence Loom

CI CodeQL License

Evidence Loom is a local-first desktop workspace for multi-agent market research. It packages a Next.js interface, a Tauri desktop shell, and an embedded TradingAgents research core into one auditable workflow.

Evidence Loom is an independent community project and is not affiliated with or endorsed by TauricResearch. Outputs are generated from probabilistic models and third-party data. They are not financial, investment, legal, or trading advice.

中文说明

desktop-readme.mp4

Desktop workspace

Evidence Loom desktop task center showing the multi-agent research workflow

What it does

  • Coordinates market, sentiment, news, fundamentals, research, trading, and risk agents.
  • Runs locally through a packaged sidecar on desktop; no Evidence Loom cloud account is required.
  • Keeps task history and reports on the device, with frozen report versions for review and export.
  • Shows output-format validation and text fallback in reports; legacy reports retain an explicit unknown status.
  • Saves the exact sanitized research inputs, actual provider attempts, full-precision normalized data, and citation IDs with each run; report versions and HTML/Markdown/JSON exports retain the evidence bundle and content hashes.
  • Stores desktop API keys in macOS Keychain or Windows Credential Manager.
  • Supports OpenAI-compatible APIs, Anthropic, Google, Azure OpenAI, DeepSeek, Qwen, GLM, MiniMax, OpenRouter, and local/custom endpoints.

Research quality, evidence provenance, reproducibility, and analyst acceptance remain active development work. See the professional quality criteria and evidence.

Saved citation IDs identify captured sources; they do not prove factual support. Unknown publication dates and historical content vintages remain explicit. See the evidence bundle contract for retention and cutoff limits.

Supported platforms

Platform Installer Source build
macOS Apple Silicon Signed and notarized DMG Supported
macOS Intel Signed and notarized DMG Supported
Windows x64 Authenticode-signed installer Supported
Linux Not published for the first release Supported for technical users

Only download installers from this repository's GitHub Releases. A release is withheld when platform signing or notarization cannot be completed.

Run from source

Prerequisites: Python 3.10–3.13, uv, Node.js 22 with npm, and Rust 1.95.

git clone https://github.com/simonguo/evidenceloom.git
cd evidenceloom
cp .env.example .env
uv sync --locked --group dev
npm --prefix frontend ci

Start the browser development UI at http://127.0.0.1:31741:

npm --prefix frontend run dev

The browser development server and npm --prefix frontend run start bind to 127.0.0.1 by default. Use Next.js's --hostname option after npm's -- separator to choose another listening address explicitly. Tauri continues to use the local development server on port 31741.

Start the Tauri development app:

npm --prefix frontend run tauri:dev

Run the upstream-compatible CLI:

uv run tradingagents

Selected analysts run concurrently up to TRADINGAGENTS_ANALYST_CONCURRENCY_LIMIT (default 1); the desktop uses its concurrency setting. TRADINGAGENTS_MAX_TOOL_ROUNDS bounds each analyst's tool rounds (default 20), after which it is asked to finish its report. Optional TRADINGAGENTS_MAX_TOKENS and TRADINGAGENTS_LLM_MAX_RETRIES bound model output and SDK retries. Set TRADINGAGENTS_CHECKPOINT_ENABLED=true or pass --checkpoint to resume compatible CLI runs; changed run settings start a fresh checkpoint. See .env.example for provider-specific thinking controls and the holding period used to settle memory entries.

TRADINGAGENTS_HOLDING_PERIOD_DAYS must be a positive integer (default 5). Settlement uses completed daily closes and waits until the exit date has passed in both local time and UTC, so a live candle cannot permanently settle a memory entry. This can delay settlement until the following day.

The Portfolio Manager's explicit rating is authoritative. A decision with no readable rating displays REVIEW and can be filtered separately. Historical tools enforce the run's instrument and cutoff date; financial records without a known publication date are withheld for historical runs. Missing historical data remains a limitation rather than a reconstructed filing vintage.

Run the Docker CLI environment:

docker compose run --rm evidenceloom

Architecture and data flow

Next.js UI
  ├─ web development mode → local Next.js API routes → Python research core
  └─ desktop mode → restricted Tauri IPC → Rust process controller → packaged Python sidecar
                                                        ├─ LLM provider APIs
                                                        └─ market/news data providers

Desktop settings and task metadata use a local SQLite database. Secret values are never returned by desktop snapshot APIs: Rust retrieves them from the operating-system credential store and injects them only into the sidecar process. Web-mode keys stay in memory for the current browser session and are not written to localStorage.

Prompts, tickers, dates, retrieved market context, and generated content may be sent to the model and data providers you configure. Provider billing, retention, geographic processing, and acceptable-use terms apply independently. Review PRIVACY.md before using real portfolio information.

Development checks

uv lock --check
uv run ruff check .
uv run ruff format --check .
uv run pytest

npm --prefix frontend run lint
npm --prefix frontend run typecheck
npm --prefix frontend test
npm --prefix frontend run build
npm --prefix frontend audit --audit-level=high

cargo fmt --manifest-path src-tauri/Cargo.toml --check
cargo clippy --manifest-path src-tauri/Cargo.toml --all-targets --locked -- -D warnings
cargo test --manifest-path src-tauri/Cargo.toml --locked

uv run pytest uses dummy credentials, temporary storage, and blocked network access. Tests marked integration are excluded by default. Run them explicitly with uv run pytest -m integration only when external provider calls are intended and the required credentials are configured.

The scheduled and pull-request security checks also audit the exported, hash-pinned Python runtime dependencies. Frontend production auditing remains separate from the full development-tool audit. See the dependency security record for commands and the remaining unpatched development dependency.

Build outputs and architecture-specific sidecars are generated locally and must not be committed. See frontend/SIDECAR.md and frontend/DESKTOP_DISTRIBUTION.md for packaging details.

Troubleshooting

  • The desktop app reports a missing sidecar: build the runner for the same Rust target as the app by following frontend/SIDECAR.md; never rename a runner built for another architecture.
  • The runtime check fails or reports an outdated sidecar: rebuild with a Python interpreter matching the app's target. The check requires actual research imports; a bootstrap ready response alone is insufficient. Packaged cold-import checks have a 90-second deadline, and full analysis startup latency remains under investigation.
  • A provider is still shown as unconfigured: save its key again and approve the macOS Keychain or Windows Credential Manager prompt. Evidence Loom deliberately does not fall back to plaintext storage.
  • Port 31741 is already in use: stop the conflicting process or set a different development port consistently in the frontend and Tauri development configuration.
  • A clean install fails: confirm the supported Python, Node, npm, and Rust versions above, then run the commands with --locked/npm ci; do not regenerate lockfiles as a workaround.
  • Model or market-data requests fail: verify the selected provider, endpoint, account quota, regional availability, and symbol format. See SUPPORT.md before opening an issue.

Community and security

License and upstream

Evidence Loom is licensed under Apache License 2.0. Its modified TradingAgents core starts from v0.2.5 at commit a5cb7cbd61d217fb0bc43f017392a861257afe6a, with selected fixes adapted from v0.5.2 at commit 8b22d43d01d9ddda5d686d093d5385884622f3de. This is a selective synchronization; the embedded package version remains 0.2.5. The internal Python module remains named tradingagents for upstream compatibility; Evidence Loom does not publish that name to PyPI.

See NOTICE, MODIFICATIONS.md, UPSTREAM.md, and THIRD_PARTY_NOTICES.md for attribution, modifications, and dependency licensing.

About

Local-first multi-agent market research desktop workspace built with Tauri, Next.js, and an embedded TradingAgents-compatible core.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

30 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages