Atlas / MCP servers / 24mlight / A-Share

A-ShareSAFE

mcp/24mlight/a-share

None

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
41 41r · 0w · 0d
Transport
stdio
License
MIT
Stars
646
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

<img src="https://img.shields.io/badge/A股数据-MCP%20工具-E6162D?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB2ZXJzaW9uPSIxLjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgd2lkdGg9IjI0IiBoZWlnaHQ9IjI0IiB2aWV3Qm94PSIwIDAgMjQgMjQiPg0KPHBhdGggZmlsbD0iI2ZmZiIgZD0iTTggMTAuOGMwIDAgMC44LTEuNSAyLjQtMS41IDEuNyAwIDIuOCAxLjUgNC44IDEuNSAxLjcgMCAyLjgtMC42IDIuOC0wLjZ2LTIuMmMwIDAtMS4xIDEuMS0yLjggMS4xLTIgMC0zLjEtMS41LTQuOC0xLjUtMS42IDAtMi40IDAuOS0yLjQgMC45djIuM3pNOCAxNC44YzAgMCAwLjgtMS41IDIuNC0xLjUgMS43IDAgMi44IDEuNSA0LjggMS41IDEuNyAwIDIuOC0wLjYgMi44LTAuNnYtMi4yYzAgMC0xLjEgMS4xLTIuOCAxLjEtMiAwLTMuMS0xLjUtNC44LTEuNS0xLjYgMC0yLjQgMC45LTIuNCAwLjl2Mi4zeiI+PC9wYXRoPg0KPC9zdmc+">

[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://github.com/astral-sh/uv) [![MCP](https://img.shields.io/badge/MCP-Protocol-FF6B00?style=flat-square&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCIgd2lkdGg9IjI0IiBoZWlnaHQ9IjI0Ij48cGF0aCBkPSJNMTIgMkM2LjQ4NiAyIDIgNi40ODYgMiAxMnM0LjQ4NiAxMCAxMCAxMHMxMC00LjQ4NiAxMC0xMFMxNy41MTQgMiAxMiAyem0tMSAxNHY1LjI1QTguMDA4IDguMDA4IDAgMCAxIDQuNzUgMTZ6bTIgMGg2LjI1QTguMDA4IDguMDA4IDAgMCAxIDEzIDE2em0xLTJWOWg1LjI1QTguMDIgOC4wMiAwIDAAxIDE0IDE0em0tMiAwSDYuNzVBOC4wMiA4LjAyIDAgMDEgMTEgMTR6bTAtNlY0Ljc1QTguMDA4IDguMDA4IDAgMCAxIDE5LjI1

Read from source at commit 86a4afb0f335OBSERVED · 2026-09-28
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add a-share-mcp -- uvx a-share-mcp
claude-desktop
{
  "mcpServers": {
    "a-share-mcp": {
      "command": "uvx",
      "args": [
        "a-share-mcp"
      ]
    }
  }
}
03

Exposed tools (41)

41 read · 0 write · 0 destructive.

ToolRiskDescription
get_adjust_factor_dataread
get_all_stockread
get_balance_datareadQuarterly balance sheet data.
get_cash_flow_datareadQuarterly cash flow data.
get_deposit_rate_datareadBenchmark deposit rates.
get_dividend_dataread
get_dupont_datareadQuarterly Dupont analysis data.
get_fina_indicatorread
get_forecast_reportreadEarnings forecast report within date range.
get_growth_datareadQuarterly growth capability data.
get_historical_k_dataread
get_hs300_stocksreadCSI 300 constituents.
get_index_constituentsreadGeneric index constituent fetch (hs300/sz50/zz500).
get_industry_membersreadGet all stocks in a given industry on a date.
get_last_n_trading_daysreadReturn the last N trading dates.
get_latest_trading_datereadGet the latest trading date up to today.
get_loan_rate_datareadBenchmark loan rates.
get_market_analysis_timeframereadReturn a human-friendly timeframe label.
get_money_supply_data_monthreadMonthly money supply data.
get_money_supply_data_yearreadYearly money supply data.
get_month_end_trading_datesreadReturn month-end trading dates for a given year.
get_operation_datareadQuarterly operation capability data.
get_performance_express_reportreadPerformance express report within date range.
get_profit_datareadQuarterly profitability data.
get_recent_trading_rangereadReturn a date range string covering the recent N trading days.
get_required_reserve_ratio_datareadRequired reserve ratio data.
get_stock_analysisread
get_stock_basic_inforead
get_stock_industryreadGet industry classification for a specific stock or all stocks on a date.
get_suspensionsread
get_sz50_stocksreadSZSE 50 constituents.
get_trade_datesread
get_zz500_stocksreadCSI 500 constituents.
is_trading_dayreadCheck if a specific date is a trading day.
list_industriesreadList distinct industries for a given date.
list_tool_constantsread
next_trading_dayreadGet the next trading day after the given date.
normalize_index_codereadNormalize common index codes to Baostock format.
normalize_stock_codereadNormalize a stock code to Baostock format.
previous_trading_dayreadGet the previous trading day before the given date.
search_stocksread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:5
<img src="https://img.shields.io/badge/A股数据-MCP%20工具-E6162D?style=for-the-badge&logo=data:image/svg+xml;base64,PHN2ZyB2ZXJzaW9uPSIxLjEiIHhtbG5zPSJodHRwOi8vd3d3LnczLm9yZy8yMDAwL3N2ZyIgd2lkdGg9IjI0IiBoZ
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:9
[![Package Manager](https://img.shields.io/badge/uv-package%20manager-5A45FF?style=flat-square&logo=data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMjQiIGhlaWdodD0iMjQiIHZpZXdCb3g9IjAgMCAyNCAyNCIgZmlsbD0ibm
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:10
[![MCP](https://img.shields.io/badge/MCP-Protocol-FF6B00?style=flat-square&logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCIgd2lkdGg9IjI0Ii

Gates applied: no_behavioural_pass.

Audited 2026-09-28 · audit v0.4.1 · source sha 86a4afb0f335full audit observations/trust-audit/mcp-server/24mlight__a-share.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-2886a4afb0f335SAFEB89first audit
06

Questions

What is the A-Share MCP server?

None

What tools does A-Share expose?

41 in total: 41 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is A-Share safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does A-Share need?

No credential environment variables were found in its source, so it appears to need none.

How does A-Share run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as a-share-mcp.

How current is this page?

The grade is for one exact copy of the source (86a4afb0f335), read on 2026-09-28. The repository is watched and re-audited when it changes.

Advertisement