# Gendangzou's install contract needs a version tag, and it has none

> Gendangzou is a Python skill that gives an AI agent traceable research over Chinese equity market sectors, tying policy documents, authoritative media, capital flows, companies and ETFs together while keeping the conclusions at sector level. The engineering is unusually disciplined: one package shared across five agent hosts, a three-layer dependency that only points one way, and an update check that caches a tag and never downloads anything without consent. The catch is in its own install contract, which refuses to install from a branch and has no tag to install from.

**MobiusQuant/Gendangzou-skill** — 面向 AI Agent 的可溯源 A 股板块研究 Skill，贯通政策、权威媒体、市场资金、公司与 ETF，支持实时查询、研究编排和二次应用开发。

- Repository: https://github.com/MobiusQuant/Gendangzou-skill
- Website: https://gendangzou.mobiusquant.ai
- Stars: 308 · Forks: 1
- Language: Python
- License: Apache-2.0
- Published: 2026-09-18 · Updated: 2026-09-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/mobiusquant-gendangzou-skill

## The install contract refuses a branch, and there is no tag

Read the manual installation section and it draws a line in the ground. Stable versions are git tags matching a strict three-part pattern, and installation is meant to resolve the tag to a full commit identifier and then download the source archive for exactly that commit, or clone the specific tag.

```bash
git clone --depth 1 \
  --branch vX.Y.Z \
  https://github.com/MobiusQuant/Gendangzou-skill.git \
  gendangzou-skill
```

Then come two rules that make this stricter than most projects. If the repository has no stable tag, that is treated as no stable version having been released, and the default branch is explicitly not substituted. And the version file inside the installed content must match the tag, with the whole directory structure preserved rather than just the single skill description file being copied. Now the awkward part. This repository has no GitHub releases at all, and its last push was 2026-07-28. By the project's own definition it has therefore never published a stable version, and the command above has no tag to fill in. That is not necessarily an oversight, since a tag may exist in the git history without a release entry, but it is the first thing to resolve before you rely on the skill.

## One package, five agent hosts, and no host detection

Five agent platforms are listed as supported, and the table's real content is the second column, because it says who is responsible for what. One host loads the whole directory through its own skill or project-extension mechanism. Another installs through its native mechanism and loads capabilities from the description file on demand. Three more, named in the table, use the same generic package and handle local registration, permissions and the task workspace themselves, or the install directory and runtime integration. Then a paragraph that is unusually direct about scope. All platforms share one description file, one API SDK, one app catalogue and one install protocol. The repository does not probe which host it is running in, does not maintain platform-specific code branches, and does not modify any other agent's configuration. Installation is one sentence to the agent you already use, naming a repository URL, and the project never asks you to choose a host type.

## The update check downloads nothing, ever, without consent

The update design is the part of this repository most worth copying, because it separates noticing a change from acting on one. On the first call of each day the skill queries GitHub directly for stable tags and caches four things locally: the check date, the entity tag, the tag itself and the commit identifier. Two negatives follow. That check does not go through the project's own business API, so it cannot be blocked by an outage or a quota on the data side. And it does not download or overwrite any file. Downloading the source archive by commit identifier happens only after a person has explicitly agreed, and the update is then applied with whatever mechanism the host agent already uses. The failure handling is stated as well: if there is no stable tag, if GitHub is temporarily unreachable, or if the query is rate limited, existing functionality is unaffected. An update mechanism that degrades to doing nothing is worth more than one that degrades to a stale guess.

## Three layers, and the dependency arrow only points one way

The runtime architecture is a small block of text with an arrow, and it is the clearest statement of intent in the repository. Applications depend on the SDK, the SDK depends on the core, and the core is the base. The layer table then assigns responsibilities. The core owns authentication, local state, announcements, updates, feedback and the application lifecycle, which is to say it is the only layer allowed to know who the user is and what has been installed. The SDK is read-only API transport plus the online capability contract and shared workflows. Applications are independently loadable research tools brought in on demand. The diagram above it shows the same structure from the outside, with policy, media, market, capital, company and ETF inputs feeding the service, the service feeding the SDK, and the SDK feeding both the bundled applications and the user's own workflows. That is the point of the split: a third-party application built against the SDK inherits authentication, snapshots and evidence handling without reimplementing any of it.

## Seven applications, each its own directory and loadable on demand

The bundled applications are listed with the discipline of a package manager rather than a feature list. Each one is a separate directory that can be installed, updated, disabled or uninstalled on its own, and the agent is instructed to load only the application description that matches the current request, so asking a question about an evening news broadcast does not drag in the ETF mapping code. The seven cover realtime sector radar by polling the material stream and comparing rolling windows, the site's daily sector report as a downloadable image, a weekly report aggregating authoritative policy, three signals, sector moves and linkages, sector dynamics explaining relative strength and linkages, a company membership audit that checks the facts, the transmission logic and the traceable materials behind a company's sector membership, ETF exposure mapping, and broadcast interpretation mapped onto existing sectors. The ETF one states its method explicitly: exposure is computed from the official portfolio basket plus company-sector relationships, and the output shows the basket date, the adjusted exposure and the evidence chain.

## Conclusions stop at the sector, on purpose

A block labelled research boundary is the most carefully written part of the readme, and it is the part to read before trusting any output. Conclusions always land on sectors. Companies and exchange-traded funds are only ever a mapping, an exposure or a confirmation of something. Policy, media, market attention and capital signals are explained separately rather than merged into one narrative. Contemporaneous performance is not to be written as definite causation. And the skill does not offer individual stock or fund recommendations, entry or exit points, or return forecasts, with the user bearing the risk of any decision made from what it produces. The footer repeats the point in one line, saying that public material and historical statistical observation do not constitute investment advice, a trading recommendation or a return forecast. For a research tool this is the difference between a measurement instrument and an adviser, and it is stated in the place a user will actually see it.

## Anonymous by default, with a token only when the server insists

Installation is followed by a verification step, and the verification step doubles as the authentication design. Three commands run from the installed skill's root directory: a diagnostic over the applications, a listing of them in the format an agent consumes, and a bootstrap of the API with a forced flag. The diagnostic is expected to return a specific success value. Then the authentication rule: the API is anonymous by default, and a token is only obtained and configured when the server explicitly replies that authentication is required, at which point you register on a token application page and set it with a dedicated subcommand. That ordering is deliberate and worth copying, because it means an evaluation of the skill costs nothing and requires no account, while a user who hits a quota boundary is walked to the upgrade rather than the other way round. The environment requirements section closes the picture: Python 3.10 or newer, HTTPS reach to GitHub and the API host, and nothing else installed in advance.

## Core queries use only the standard library, one app needs a browser

The dependency story is short. Core queries run on the Python standard library, with no third-party packages required beforehand, which is why the verification commands work immediately after a clone. Exactly one feature adds weight: exporting the daily report as an image needs a headless browser and its driver, and only at the moment you actually use it, not at install time. Everything else that could have been a dependency is not one. The repository also separates development scripts from runtime verification, and says so explicitly: three commands under a tools directory validate the skill, run its tests and build a release into an output directory, and the note under them states that these are for working on the source repository and are not part of checking an installed copy. That separation is a small discipline with a large payoff, because it stops a developer from concluding that a working checkout is evidence that an installed skill is sound.

## Conclusion

Gendangzou fits a China-market analyst who wants sector-level research with an evidence trail rather than individual stock calls, and who works inside one of the five supported agent hosts. It does not fit anyone who wants reproducible installs today, because the project's own rules refuse a branch install and the repository carries no tagged release. Before you use it, confirm with the maintainers which commit is meant to be the current one, because the update path is designed to wait for a tag rather than guess one, and read the research boundary before you rely on any output, since the tool is built to explain signals separately and to refuse causal claims. If you are writing against it, use the published machine capability contract rather than reverse-engineering command paths from examples.

## FAQ

### What is the Gendangzou skill?

It is an agent skill that packages traceable Chinese equity market sector research. It connects policy documents, authoritative media, market attention, capital confirmation, and company and fund relationships into one queryable layer, and it is also a base for building further applications through a unified API SDK and an application package specification.

### How do I install the Gendangzou skill?

The documented route is to ask the agent you are already using to install the repository URL, and it handles the directory and registration with its own mechanism. A manual route clones a strict version tag at depth one. The installed content must keep its whole directory structure, and its version file must match the tag.

### Does Gendangzou need an API key?

Not to begin with. The API is anonymous by default and you only register and configure a token when the server explicitly replies that authentication is required. A diagnostic command and a forced bootstrap are used to verify the installation, and the diagnostic is expected to report success.

### Which agent platforms does Gendangzou support?

Five are listed, sharing the same package, SDK, app catalogue and install protocol. The repository does not probe which host it is running in, keeps no platform-specific code branches, and does not modify other agents' configuration; each host handles registration, permissions and workspace through its own mechanism.

### Does Gendangzou make stock recommendations?

No, and the boundary is stated explicitly. Conclusions always land on sectors, companies and funds appear only as mapping, exposure or confirmation, the policy, media, attention and capital signals are explained separately, contemporaneous performance is not presented as causation, and there are no buy or sell points or return forecasts.

## Sources

- [Issues](https://github.com/MobiusQuant/Gendangzou-skill/issues)
- [License: Apache-2.0](https://github.com/MobiusQuant/Gendangzou-skill/blob/main/LICENSE)
- [MobiusQuant/Gendangzou-skill on GitHub](https://github.com/MobiusQuant/Gendangzou-skill)
- [Project website](https://gendangzou.mobiusquant.ai)
- [README](https://github.com/MobiusQuant/Gendangzou-skill/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/mobiusquant-gendangzou-skill
