Atlas / MCP servers / huweihua123 / Stock

StockBLOCK

mcp/huweihua123/stock-3

专业的金融市场数据 MCP 服务器 - 支持A股/美股/加密货币,原生 MCP 协议,AI Agent 友好

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
23 23r · 0w · 0d
Transport
streamable-http
License
—
Stars
178
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

开源金融数据 MCP / HTTP 服务,面向 AI Agent、量化脚本和普通后端集成。

中文

这是什么

stock-mcp 是一个开源金融数据服务,提供两套对外接口:

  • MCP:给 Claude Desktop、Cursor、DeerFlow、各类 Agent 使用
  • HTTP API:给普通后端、脚本和服务直接调用

它的定位不是“给投资建议”,而是提供:

  • 稳定的数据源接入
  • 标准化的金融工具能力
  • 适合 Agent 使用的 MCP tool / artifact 输出
  • 适合代码执行工作流的 CSV / JSON 数据导出

一键启动

如果你只是想先把服务跑起来,最短路径就是:

git clone https://github.com/yourusername/stock-mcp.git
cd stock-mcp
cp .env.example .env
docker compose up -d --build

启动后默认可访问:

  • http://127.0.0.1:9898/health
  • http://127.0.0.1:9898/docs
  • http://127.0.0.1:9898/mcp

默认 Docker 栈会一起启动:

  • stock-mcp
  • redis
  • postgres

默认端口:

  • stock-mcp: 127.0.0.1:9898
  • postgres: 127.0.0.1:15432

说明:

  • 15432 是为了避免占用你本机已有的 5432
  • 容器内部仍然使用 postgres:5432
  • 如果你想修改宿主机映射端口,改 DOCKER_POSTGRES_PORT 即可

核心功能

1. 市场数据

  • A 股、美股、ETF、指数、加密资产行情
  • 日线 / 分时 / K 线数据
  • 多市场 ticker 解析与标准化
  • 多数据源回退

2. 技术分析

  • RSI、MACD、均线、布林带等常见指标
  • K 线形态识别
  • 支撑 / 压力位分析
  • 趋势与动量辅助分析

3. 基本面与研究

  • 估值与基础财务指标
  • 美股宏观和行业研究工具
  • 基于 Tavily 的统一新闻检索
  • 资金流与筹码分布

4. 公告与文档

  • SEC / EDGAR filings
  • A 股公告处理
  • 文档 chunk / markdown / 结构化提取

5. Agent / Code Workflow 友好能力

  • MCP tools 统一注册
  • MCP artifact 减载,避免把大 blob 直接塞进模型上下文
  • code-export HTTP 接口,可直接导出 CSV / JSON 给代码执行型 agent

支持的主要数据源

国内源:

  • Tushare
  • Akshare
  • Baostock

国外源:

  • Yahoo / yfinance
  • Finnhub
  • Alpha Vantage
  • Twelve Data
  • FRED
  • CCXT
  • Crypto
  • EDGAR

HTTP API 能做什么

当前 HTTP 路由主要分为这些组:

  • /api/v1/market/*
  • 行情、K 线、技术指标、市场数据查询
  • /api/v1/fundamental/*
  • 基本面与估值
  • /api/v1/money-flow/*
  • 资金流分析
  • /api/v1/news/*
  • 统一新闻检索与个股新闻搜索
  • /api/v1/filings/*
  • SEC / A 股公告与文档处理
  • /api/v1/code-export/*
  • 面向代码执行工作流的数据导出
  • /health
  • 健康检查
  • /docs / /redoc
  • OpenAPI 文档

也就是说,这个项目不是只有 MCP。

如果你不打算接 MCP 客户端,完全可以只把它当普通 HTTP 服务来用。

Read from source at commit 689bb7888439OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add stock-mcp --env ALPHA_VANTAGE_API_KEY=${ALPHA_VANTAGE_API_KEY} --env MINIO_ACCESS_KEY=${MINIO_ACCESS_KEY} --env MINIO_SECRET_KEY=${MINIO_SECRET_KEY} -- uvx stock-mcp
claude-desktop
{
  "mcpServers": {
    "stock-mcp": {
      "command": "uvx",
      "args": [
        "stock-mcp"
      ],
      "env": {
        "ALPHA_VANTAGE_API_KEY": "${ALPHA_VANTAGE_API_KEY}",
        "MINIO_ACCESS_KEY": "${MINIO_ACCESS_KEY}",
        "MINIO_SECRET_KEY": "${MINIO_SECRET_KEY}"
      }
    }
  }
}
03

Exposed tools (23)

23 read · 0 write · 0 destructive.

ToolRiskDescription
_toolreadreturn name
alphavantage_fetch_to_jsonreadreturn await service.export_alphavantage_json(function, symbol, extra_params or {})
calculate_support_resistancereadtry:
fetch_ashare_filingsreadtry:
fetch_event_sec_filingsreadtry:
fetch_periodic_sec_filingsreadtry:
generate_trading_signalreadtry:
get_asset_inforeadtry:
get_chip_distributionreadtry:
get_document_chunksreadtry:
get_filing_markdownreadtry:
get_financial_reportsreadtry:
get_kline_datareadtry:
get_latest_newsreadtry:
get_money_flowreadtry:
get_north_bound_flowreadtry:
get_real_time_pricereadtry:
get_stock_newsreaddel ctx
get_technical_indicatorsreadtry:
get_us_news_sentimentreadif ctx:
get_us_valuation_metricsreadtry:
get_valuation_metricsreadtry:
tushare_fetch_to_csvreadreturn await service.export_tushare_csv(api_name, kwargs or {})
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (9)

HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/server/config/settings.py:121
f"postgresql://{self.user}:{self.password}@{self.host}:{self.port}/{self.database}"
HIGHHard-coded secrets · secret.db_uri · CWE-798, CWE-321
src/server/infrastructure/connections/postgres_connection.py:28
dsn = f"postgresql://{user}:{password}@{host}:{port}/{database}"
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/server/infrastructure/connections/redis_connection.py:27
logger.info(f"🔍 Redis config: host={host}, port={port}, db={db}, has_password={bool(password)}")
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:40
- `http://127.0.0.1:9898/health`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:41
- `http://127.0.0.1:9898/docs`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:42
- `http://127.0.0.1:9898/mcp`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:315
curl -X POST http://127.0.0.1:9898/api/v1/technical/indicators/calculate \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:327
curl -X POST http://127.0.0.1:9898/mcp \

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-06 · audit v0.4.1 · source sha 689bb7888439full audit observations/trust-audit/mcp-server/huweihua123__stock-3.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06689bb7888439BLOCKD69first audit
06

Questions

What is the Stock MCP server?

专业的金融市场数据 MCP 服务器 - 支持A股/美股/加密货币,原生 MCP 协议,AI Agent 友好

What tools does Stock expose?

23 in total: 23 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Stock safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Stock need?

It reads ALPHA_VANTAGE_API_KEY, MINIO_ACCESS_KEY and MINIO_SECRET_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Stock run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as stock-mcp.

How current is this page?

The grade is for one exact copy of the source (689bb7888439), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement