mrkeyoor.com_
Wed 30 Sept 08:12 UTC
AI Toolsevaluationupdated 26 Aug 2026

nofx review

NOFX is a self-hosted trading terminal where a language model reads market and account data, proposes actions, and can place orders through connected exchanges. A Go runtime applies position, exposure, stop, cooldown, and drawdown rules outside the model, while a React dashboard records decisions and results.

+39stars / 7d
Verdict

Our NOFX run built successfully and passed 24 tests, but open reports still touch order duplication, backtest timing, and OKX equity used for sizing. Study it on testnet or with money you can lose, not as an unattended home for serious capital. Its code-enforced limits are sensible, yet latest images, no third-party audit, and no GitHub release object leave too much deployment and execution risk with the operator.

We ran it

Lab card: what happened when we ran nofxScreenshot of nofx (vergex.trade/download)
Install✓ · 67s270 packages
Build✓ · 119s
Tests✓ · 119s48 passed · 0 failed of 48 (go test)
Repo647 files~122,028 lines of source · 27.5 MB · 9 CI workflows

Answers from our run

Does nofx build from source?

Dependencies installed in 67 seconds (270 packages), and the build succeeded in 119 seconds. We cloned commit 638d404 into a clean Debian container with 3 CPUs and no project-specific setup.

Do nofx's tests pass?

Yes: 48 of 48 passed when we ran the project's own test command (go test). Some failures need services or credentials a bare container does not have.

Who should not use nofx?

Anyone who cannot lose the full account balance: the project's disclaimer says losses can exceed the initial deposit and AI behavior may be unpredictable.

What are the alternatives to nofx?

Freqtrade, Jesse, LEAN. Our NOFX run built successfully and passed 24 tests, but open reports still touch order duplication, backtest timing, and OKX equity used for sizing.

Setup3/5Build passed; wallets, exchanges, models, and host security remain
Docs4/5Detailed setup and risk controls with clear funding requirements
Community4/5August 26 issue and PR activity across a 518-item queue
Maturity2/524 tests pass, but live-money defects and release gaps remain

Who it’s for

Experienced automated-trading developers studying language models inside a constrained execution loop.
Researchers willing to use testnet accounts, tiny isolated balances, and constant monitoring.
Self-hosters who can secure exchange credentials, wallet keys, the API, and persistent trading data.
Contributors interested in exchange adapters, prompt contracts, risk controls, and decision logs.

Who it’s NOT for

Anyone who cannot lose the full account balance: the project's disclaimer says losses can exceed the initial deposit and AI behavior may be unpredictable.
Traders who need backtests to match live cadence before deployment: issue #1405 documents different timing models that materially change decision frequency.
Aster users relying on repeated model-managed protective-order updates: issue #998 reports duplicate stop orders reaching the exchange limit.
OKX users who cannot inspect the current equity calculation: open pull request #1539 says unrealized P&L is counted twice and affects position-size caps.
Security or compliance teams requiring an independently audited release: the security policy says no third-party audit is complete, while GitHub returns no latest release.
Operators who need reproducible upgrades: the production Compose file uses latest, and the documented update pulls newer images in place.

Setup reality

Our commit c04697d install succeeded in 83 seconds and added 270 packages. The build passed in 188 seconds. Go tests finished in 157 seconds with 24 passed and 0 failed out of 24.

A usable trader needs more than a successful build. The first owner must register, model access must work, a Base wallet may need USDC for metered calls, and an exchange account needs credentials plus trading funds. Exchange keys should block withdrawals and belong to an isolated subaccount.

The repository has 9 CI workflow files and a Compose file, but no Dockerfile and no directory literally named tests. Source work needs Go 1.21 or newer and Node.js 18 or newer. The published Compose stack exposes frontend and backend ports and follows latest, so network controls and version pinning are operator jobs.

Nine exchanges sit behind code-enforced risk limits

NOFX is a complete trading terminal rather than a prompt that prints buy and sell suggestions. A Go service gathers balances, positions, candles, indicators, funding information, and optional market-flow data. A model returns structured decisions, then runtime code checks those decisions before an exchange receives an order. The React interface shows positions, orders, statistics, strategy settings, and the reasoning stored for each cycle.

The runtime can cap concurrent positions and position value as a share of equity. It also applies entry throttles, cooldowns, exchange-side stop and target orders, profit-giveback closures, and a safe mode after repeated model failures. A preflight checks model access, wallet funds, strategy configuration, and exchange balance before Autopilot starts. Those controls constrain requests; they do not prove profitable decisions or correct adapter behavior.

The README lists 9 exchanges and 8 bring-your-own-key model providers, plus a Claw402 route paid per call in USDC. Hyperliquid coverage includes crypto perpetuals and advertised tokenized markets such as equities, commodities, indices, foreign exchange, and pre-IPO contracts. Availability and legality still depend on the venue and jurisdiction. Each integration needs its own small test account because support breadth does not mean identical order semantics.

What happened when we ran it

Our sandbox installed 270 packages from commit c04697d in 83 seconds. The checkout contained 645 files, about 121,820 source lines, and 27.5 MB. Building the project succeeded in 188 seconds in an unprivileged Debian container with 3 CPUs and 8 GB of RAM. No exchange credentials, model keys, wallet secrets, or trading funds were provided.

The Go test command finished in 157 seconds with 24 passed and 0 failed out of 24. The repository has 9 CI workflow files and a Compose file, though our scan found no Dockerfile and no directory literally named tests. The successful result shows the checked-out code compiled and its discovered Go tests passed. It does not exercise a live venue, paid model call, wallet, browser flow, or full Autopilot cycle.

That distinction matters more here than for an ordinary dashboard. A valid API response can still carry the wrong balance convention, an exchange can interpret protective orders differently, and a model can produce an allowed but poor trade. Our 24 passing tests justify code evaluation, while live use requires testnet trials for entry, resize, stop, target, cancel, reconciliation, emergency close, and restart recovery on the exact exchange adapter.

A one-command install still leaves custody with you

The documented installer downloads the production Compose file and opens the terminal at port 3000. The backend defaults to port 8080. The first account registered becomes the owner, so a remote instance should remain firewalled until registration is complete. HTTPS, host patches, backups, access logs, and restrictions on both ports belong in the first deployment.

Initial Hyperliquid guidance asks for at least $1 USDC on Base for the AI fee wallet and at least $12 USDC for trading. Those amounts demonstrate the guided flow. They say nothing about a sensible account size after model charges, exchange fees, funding payments, slippage, margin rules, and liquidation risk. The project disclaimer recommends testnet and warns that users can lose all or more than their deposit.

Stored exchange credentials are described as encrypted at rest, but the running service must also hold the means to decrypt them. A compromised host can target both data and keys. Use a dedicated exchange subaccount, disable withdrawals, apply an IP allowlist where the venue supports one, keep only a disposable balance, and monitor orders outside NOFX. Model services also receive the market and account context needed to decide, so self-hosting does not keep the whole workflow local.

Open order and equity reports affect real money

Issue #998 reports that an Aster setup repeatedly created protective stop orders when the model asked to move a stop, eventually reaching the exchange's order limit. The reporter says existing open orders were absent from the model context. Pull request #1002 proposes adding them, but it remains open. Until the change is merged and tested on the deployed adapter, repeated stop management needs independent order monitoring.

Open pull request #1539 describes an OKX balance error with direct sizing consequences. According to the change, OKX totalEq already includes unrealized P&L, while generic consumers add that value again. The dashboard and model then see inflated equity, and position-value caps use the larger figure. The proposed fix reports live verification, but an open pull request is not proof that the installed branch contains it.

Backtests have a separate mismatch. Issue #1405 says historical runs schedule decisions by a number of bars, while live trading uses a fixed time interval. Its example produces very different decision frequencies, so fees, trade count, and observed risk are not directly comparable. Treat the current backtest as a research aid. Do not use an attractive result as the sole permission to enable live Autopilot.

latest images weaken an otherwise active project

GitHub recorded the last branch push on August 20, 2026, and issues and pull requests were updated on August 26. The repository had 12,758 stars and 518 open issues and PRs combined when fetched. The current activity spans exchange accounting, model context, external data, and interface translation. The large combined count includes proposed changes, so it is not a count of confirmed defects.

Release discipline is the harder concern. GitHub's latest-release endpoint returned no release object, while the security policy calls v3.x stable. The production Compose file points both backend and frontend at latest. That makes the deployed artifact mutable unless the operator records and pins image digests. For software controlling exchange credentials and orders, stage every update on testnet and keep the prior images, database, environment file, and encryption material available for rollback.

NOFX puts hard constraints outside the model and keeps a decision record. Our 188-second build and 24 passing tests support testnet experimentation. Open execution reports, no third-party audit, and mutable deployment tags rule out meaningful unattended capital.

Alternatives

ProjectWhat it isPick it when
Freqtrade gh↗A crypto bot centered on coded strategies, backtesting, optimization, and dry runs.pick this instead when repeatable rules and an established testing workflow matter more than model autonomy.
JesseA Python framework for developing, testing, and running explicit crypto strategies.pick this instead when you want to own the strategy logic and compare it against historical data before live use.
LEAN gh↗A Python and C# algorithmic trading engine for research, backtesting, and live markets.pick this instead when multi-asset quantitative research and deterministic execution are the primary requirements.

What people are saying

  1. [github-trending] NoFxAiOS/nofx

Sources

  1. NOFX repository and README
  2. NOFX disclaimer
  3. NOFX security policy
  4. NOFX production Compose file
  5. Aster duplicate stop-order report
  6. Backtest and live timing mismatch report
  7. OKX equity calculation pull request

More ai tools reviews

dream-loop · Codex-Minecraft-Gameplay · kun · screenwriting-skills · holo-card-studio · microduck-replica · the whole board →