4 min read

AI Hedge Fund: LLM Investor Agents That Paper Trade (GitHub, Scanned)

An educational fund simulator where LLM investor personas pick stocks for backtests and paper trading.

AI Hedge Fund logo
✅
Scan: safe. Nothing to warn about. A small Python codebase that only talks to the market-data API and the model provider you choose. Scanned Oct 2, 2026; the full report is below.

AI Hedge Fund is a proof of concept for running a stock portfolio with language-model agents. Strategies are built from "models": LLM personas of Warren Buffett, Charlie Munger, Benjamin Graham, Peter Lynch and Stanley Druckenmiller that each read fundamentals and earnings and return a conviction score with a written thesis, plus systematic quant models such as post-earnings drift. A strategy blends their signals, a fund allocates capital across strategies, and a terminal app lets you backtest a fund against a benchmark or run it as a paper-trading fund that advances one market session at a time with fake money.

Virat Singh (virattt) started it in late 2024 and it has about 64,000 stars, helped by TikTok creators who featured it in AI-trading videos. The current 2.x version is a rebuild: install it with pipx as aihf, and every paper session is appended to a hash-chained ledger in your home folder so the track record cannot be quietly reset. It is MIT-licensed and the README is blunt: it is for education and research, it places no real trades, and it is not investment advice.

Who it is for

Developers and finance students curious how multi-agent LLM systems reason about stocks, and anyone who wants to test an investing idea on paper before trusting it.

Getting started

1. Install the CLI (or: uv tool install aihf)

pipx install aihf

2. Launch the terminal app; it asks for a Financial Datasets key and one model key on first run

aihf

3. Or run it from source

git clone https://github.com/virattt/ai-hedge-fund.git && cd ai-hedge-fund && poetry install && poetry run aihf

You need a Financial Datasets API key for prices and fundamentals and one model key (Anthropic, OpenAI, DeepSeek, Google, xAI or Kimi). Keys are saved in plain text to ~/.hedge-fund/.env. Every agent call costs tokens, so long backtests over many tickers add up.

Safety scan

We cloned virattt/ai-hedge-fund at commit 78b779c on Oct 2, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no pattern hits, no committed binaries and no install hooks across 115 files and about 17,500 lines of Python.
  • The network hosts are the ones you configure: api.financialdatasets.ai for market data and the model providers (Anthropic, OpenAI, DeepSeek, Google, xAI, Kimi, TypeSafe). There is no brokerage integration; the brokers folder holds a simulator and a paper ledger only.
  • poetry.lock pins 108 packages with 12 known advisories (1 critical, 4 high). The critical and one high are in black, the code formatter, a development tool. The LangChain path-traversal advisory concerns legacy prompt-loading functions this project does not call, and the urllib3 ones affect streaming and proxy edge cases.
  • API keys are saved in plain text to ~/.hedge-fund/.env, which is fine on a personal machine but worth knowing on a shared one.
  • No workflows, so no CI to review. Licence present; no security policy, Dependabot, CodeQL or contributing guide.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time codeNone: nothing runs at install beyond the package manager itself.
Committed binariesNone.
CI workflowsNo GitHub Actions workflows.
Network hosts5 distinct hosts referenced from source; most often api.financialdatasets.ai, mba.tuck.dartmouth.edu, api.typesafe.ai, api.moonshot.ai. No URLs to bare IP addresses.
Known vulnerabilities12 advisories across 108 pinned packages: 1 critical, 4 high, 5 moderate, 2 low. poetry.lock: 108 packages, 12 advisories.
Project hygieneHas licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Worst known vulnerabilities (12 of 12)
AdvisorySeverityPackageSummary
GHSA-v53h-f6m7-xcgmcriticalblack@23.12.1
GHSA-3936-cmfr-pm3mhighblack@23.12.1
GHSA-qh6h-p6c9-ff54highlangchain-core@0.3.86LangChain Core has Path Traversal vulnerabilites in legacy `load_prompt` functions
GHSA-8988-9cw3-xx77highurllib3@2.7.0urllib3: HTTPS proxy TLS configuration may be ignored or overridden
GHSA-vxq7-64xx-v4gwhighurllib3@2.7.0urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory
GHSA-fj7x-q9j7-g6q6moderateblack@23.12.1Black vulnerable to Regular Expression Denial of Service (ReDoS)
GHSA-gr75-jv2w-4656moderatelangchain-anthropic@0.3.5LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
GHSA-6w46-j5rx-g56gmoderatepytest@7.4.4pytest has vulnerable tmpdir handling
GHSA-mf9w-mj56-hr94moderatepython-dotenv@1.0.0python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback
GHSA-gh4c-6fx4-qh6gmoderateurllib3@2.7.0urllib3: Chunked Deflate streaming can enter an infinite loop
GHSA-2g6r-c272-w58rlowlangchain-core@0.3.86LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
GHSA-r7w7-9xr2-qq2rlowlangchain-openai@0.3.35langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding

By the numbers

Stars63.8K
Forks11.2K
Contributors49
Commits937
Open issues55
Open pull requests121
Releases16
Latest releasev2.5.0
LicenceMIT
Main languagePython
Project age1 year
Last pushOct 2, 2026
Tracked files115
Lines of code17.5K
Checkout size1 MB

Lines by language: Python 16.7K, Markdown 604, YAML 92, TOML 60, JSON 48.

Questions

Is AI Hedge Fund free?

The code is MIT-licensed and free. Running it is not: market data comes from the Financial Datasets API and decisions from a paid model API, both billed by those providers. There is no hosted version and no subscription from the project itself.

Does AI Hedge Fund trade real money?

No. It has a simulated broker for backtests and a paper broker that tracks fake money against real market days. There is no connection to a brokerage, and the author states it is for educational purposes only and not for real trading or investment.

Can LLM agents beat the market?

Nothing in this project shows that. Persona agents produce plausible reasoning, but a backtest over a short window, on a few tickers, with a model that may have seen the period in its training data, proves little. Treat results as a way to study agent behaviour, not as a strategy.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.