Atlas / MCP servers / longsizhuo / OpenInvest

OpenInvestBLOCK

mcp/longsizhuo/openinvest

Research-grade investment decision engine for AI agents: isolated multi-agent committee, auditable verdicts, backtests with lookahead protection, published negative results

Verdict
BLOCK
Grade
D
Trust score
63 /100
Exposed tools
9 8r · 0w · 1d
Transport
stdio · streamable-http
License
MIT
Stars
87
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A self-hosted investment decision engine built for modern AI agents. Multi-agent information isolation and cross-challenge protocol, providing an auditable decision trail (Audit Trail).

[](https://www.python.org/) [](docs/wiki/20-agent-usage-tutorial.md) [](LICENSE) [](https://github.com/longsizhuo/openInvest) [](https://glama.ai/mcp/servers/longsizhuo/openInvest)

📚 Full Architecture Wiki · 🇨🇳 中文版

What is OpenInvest?

OpenInvest is a self-hosted investment decision engine built for modern AI agents.

It provides a verifiable investment committee, evidence-based reasoning, long-horizon backtesting, and auditable decision records. Instead of replacing Claude Code, Codex, Hermes, or OpenClaw, OpenInvest is designed to power them.

Live Performance & PnL

Data feed is automatically updated every 2 hours using jobs/pnl_snapshot and pushed to the pnl-data branch

Upper half: 30-day net asset value trend · Lower half: Net asset value comparison against 8 benchmark assets (transparent disclosure, not an alpha claim—the committee's proven value is

Read from source at commit ce03f0ee2bedOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add openinvest -- uvx openinvest==0.0.0 mcp
03

Exposed tools (9)

8 read · 0 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
decisionsreadGet the unified decision ledger: every committee verdict joined with
disciplinereadGet the committee
explain_decisionreadGet the full reasoning behind one committee verdict: the complete
historyreadGet the most recent trade records and committee verdict history.
live_pricesreadFetch a one-shot market backdrop: spot gold (USD/oz and CNY/gram),
news_sourcesreadList the news feed sources the crawler pulls from: the built-in default
remove_news_sourcedestructiveRemove a user-added news feed by name or URL. Built-in default feeds
statusreadGet a full snapshot of the user
strategyreadGet the user
04

Trust audit

BLOCKgrade D · trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (6 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
none-found

Findings (25)

HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
plugin/skills/invest/references/committee-protocol-hermes.md:52
File exists → **read it directly, do not re-run**, and tell the user: "<SYMBOL> has
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
plugin/skills/invest/references/onboarding.md:3
The user hasn't done first-time setup yet. **Never** tell the user to "go edit
Why it matters. asks the agent to act without the user's knowledge
MEDIUMInventory / provenance · inv.binary · CWE-1104
experiments/closed-loop-skill-test/data/closed_loop.tar.gz
closed_loop.tar.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
experiments/closed-loop-skill-test/data/holdout_baseline_2025-2026.tar.gz
holdout_baseline_2025-2026.tar.gz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
plugin/skills/invest-setup/scripts/run.sh
plugin/skills/invest-setup/scripts/run.sh
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
skills/invest
skills/invest
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
skills/invest-backup
skills/invest-backup
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
skills/invest-setup
skills/invest-setup
Why it matters. link not followed
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
src/openinvest/scheduler/runner.py:117
module = importlib.import_module(module_name)
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
experiments/sandbox/run_sandbox_v2.py:620
q2 = f"RANDOM_BETTER_OR_SIMILAR (Δacc={delta_acc_21:+.2f}pp, Δalpha={delta_alpha_21:+.2f}pp)"
MEDIUMObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
experiments/signal-eval/trend_dca.py:140
a = (1.0 + k * (sig - sbar)).clip(lower=0.0)   # 投入权重,Σa=N(总额不变)
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
remove_news_source
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
plugin/skills/invest-setup/references/onboarding-detailed.md
plugin/skills/invest-setup/references/onboarding-detailed.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
plugin/skills/invest-backup/scripts/run.sh:16
REPO_ROOT="$(cd "$SCRIPT_DIR/../../../.." && pwd)"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
plugin/skills/invest/scripts/run.sh:19
REPO_ROOT="$(cd "$SCRIPT_DIR/../../../.." && pwd)"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
skills/okf-frontmatter/scripts/run.sh:23
REPO_ROOT="${INVEST_HOME:-$(cd "$SKILL_DIR/../../.." && pwd)}"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/wiki/06-api.md:46
open http://127.0.0.1:8765/docs
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/wiki/06-api.md:49
curl http://127.0.0.1:8765/openapi.json
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/wiki/06-api.md:131
curl -X POST http://127.0.0.1:8765/api/cash/CNY/deposit \
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/wiki/06-api.md:146
curl -X POST http://127.0.0.1:8765/api/holdings -d '{
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/wiki/06-api.md:170
curl -X POST http://127.0.0.1:8765/api/holdings/import \
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/wiki/08-deployment.md:233
# 再发邮件。invest 不直接持有 Discord token——POST 给同宿主机 Discord bot 的
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
plugin/skills/invest/references/onboarding.md:22
| Q5 | DeepSeek API key & Gmail App Password? | **Optional**. The Coordinator path (chatting inside Claude Code) runs without any keys; they're only needed if you want the server to run automatically
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOInventory / provenance · inv.oversize · CWE-1104
experiments/signal-eval/out/q1_panel.pkl
experiments/signal-eval/out/q1_panel.pkl
Why it matters. 4242298 bytes not read

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha ce03f0ee2bedfull audit observations/trust-audit/mcp-server/longsizhuo__openinvest.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07ce03f0ee2bedBLOCKD63first audit
06

Questions

What is the OpenInvest MCP server?

Research-grade investment decision engine for AI agents: isolated multi-agent committee, auditable verdicts, backtests with lookahead protection, published negative results

What tools does OpenInvest expose?

9 in total: 8 read-only, 0 that write, and 1 that can delete or overwrite (remove_news_source). Every one is listed on this page with its risk.

Is OpenInvest safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (63/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OpenInvest need?

It reads CF_ACCESS_CLIENT_SECRET, CHATBOT_INTERNAL_KEY, DEEPSEEK_API_KEY, EMAIL_PASSWORD, GITHUB_TOKEN, INVEST_API_TOKEN, LLM_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OpenInvest run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as openinvest at 0.20.1.

How current is this page?

The grade is for one exact copy of the source (ce03f0ee2bed), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement