PluginBench
Skill
Review
Audit score 70

toss-investment

nomadamas/k-skill

Query Toss Securities account, holdings, and market data via official OAuth2 API with read-only access.

What is toss-investment?

This skill provides safe, read-only access to Toss Securities account information, holdings, quotes, and order history through the official OAuth2 Open API. Use it when you need to retrieve investment data without making trades or bypassing official API limitations.

  • Query account information and balances via official OAuth2
  • Retrieve current holdings and stock positions
  • Access market data, quotes, and ticker information
  • Look up order history and transaction details
  • Enforce read-only operations to prevent accidental modifications
  • Refuse unofficial workarounds when official API credentials or endpoints are unavailable

How to install toss-investment

npx skills add https://github.com/nomadamas/k-skill --skill toss-investment
Prerequisites
  • Node.js 18 or later
  • Toss Securities official OAuth2 credentials (client ID and secret)
  • User authorization via OAuth2 flow
Claude Code
Cursor
Windsurf
Cline

How to use toss-investment

  1. 1.Run `npx -y @nomadamas/k-skill@0 instruct toss-investment` to get runtime-specific setup instructions
  2. 2.Obtain official OAuth2 credentials from Toss Securities developer portal
  3. 3.Authenticate using the OAuth2 flow (do not hardcode credentials)
  4. 4.Call the appropriate API endpoints to query accounts, holdings, or market data
  5. 5.Review the full disclaimer and legal requirements before deployment

Use cases

Good for
  • Display a user's current portfolio and account balance
  • Retrieve real-time stock quotes and market information for analysis
  • Check order history and past transaction details
  • Monitor holdings across multiple accounts securely
  • Build dashboards that pull live investment data from Toss Securities
Who it's for
  • Investment portfolio managers
  • Financial advisors and analysts
  • Individual traders and investors
  • Fintech developers integrating Toss Securities data
  • Korean investment platform users

toss-investment FAQ

Can I use this skill to place trades or execute orders?

No. This skill is read-only and does not support order placement, cancellations, or payment operations. Any such action requires explicit user approval and is outside the scope of this skill.

What if the official API doesn't support a feature I need?

The skill will not bypass official API limitations or use unofficial workarounds. If a feature is unavailable through the official OAuth2 API, it is not supported.

Do I need to provide my password or credentials in chat?

No. Never share plaintext credentials. Use the official OAuth2 authentication flow, which handles credentials securely without exposing them in chat or files.

Is this skill affiliated with or endorsed by Toss Securities?

No. This is an unofficial skill that uses Toss Securities' official public API. It is not developed by, affiliated with, or endorsed by Toss Securities or its parent company.

Can I use this for bulk data collection or crawling?

No. Automated collection must be limited to personal, non-organizational lookup only. Systematic crawling, database building, or interference with Toss Securities' service is prohibited.

Full instructions (SKILL.md)

Source of truth, from nomadamas/k-skill.


name: toss-investment description: 토스증권 공식 Open API(OAuth2)로 계좌, 보유주식, 시세/종목/시장정보, 주문조회를 안전한 read-only 흐름으로 조회한다. 공식 credentials가 없거나 공식 API가 지원하지 않는 기능은 비공식 경로로 우회하지 않는다. license: MIT metadata: category: finance locale: ko-KR phase: v1

toss-investment

<!-- k-skill:cli-stub — generated by scripts/generate-skill-stubs.js; edit skill.json / instruction.md instead -->

Get the full instructions (required first step)

Run this and follow its output as the primary instructions for this skill:

npx -y @nomadamas/k-skill@0 instruct toss-investment

The CLI detects the current runtime (Dolshoi vault/CloakBrowser vs generic) and prints only the applicable instructions, always up to date. Helper files bundled with the CLI are listed by:

npx -y @nomadamas/k-skill@0 files toss-investment

Keep the CLI and every coding-agent skill install current (including Vercel Agent Skills) with:

npx -y @nomadamas/k-skill@0 update

If npx is unavailable, install Node.js 18+ or follow https://github.com/NomaDamas/k-skill#readme, or read the source instructions at https://github.com/NomaDamas/k-skill/blob/main/toss-investment/instruction.md.

Legal disclaimer (required)

This skill is not an official feature of, officially supported by, affiliated with, sponsored by, approved by, or developed in collaboration with any third-party trademark owner or service operator it identifies. Third-party names are used only to describe the skill's function, lookup target, or compatibility.

Any automated collection of publicly accessible information must be limited to personal, non-organizational lookup. Do not use this skill for systematic or bulk crawling, database building, access-control or block circumvention, or conduct that interferes with a third party's business or service.

Read the full Korean legal disclaimer, including the cited Korean Supreme Court precedents and statutory limits, before use:

npx -y @nomadamas/k-skill@0 read toss-investment references/DISCLAIMER.md

Hard rules even without the CLI

  • Never execute payment, message/email delivery, final submission, cancellation, or public posting without the user's explicit approval immediately beforehand.
  • Never ask for, print, or store plaintext credentials in chat, files, or shell arguments.
  • Never bypass legal, physical-presence, CAPTCHA, identity-proofing, or electronic-signature boundaries.