OpenFinClawCAUTION
One-stop quant-trading AI agent — research · strategy · backtest · paper trade from one prompt. Works in Claude Code, Cursor, and 20+ AI agents via MCP. 60-second install with auto Skill registration.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 中文
Your quant research team, in one prompt.
Research · strategy · backtest · paper trade — ship a complete quant workflow from a single natural-language prompt, inside Claude Code, Cursor, and 20+ AI agents.
[](https://www.npmjs.com/package/@openfinclaw/cli) [](https://www.npmjs.com/package/@openfinclaw/cli) [](https://modelcontextprotocol.io) [](LICENSE)
🚀 Try it in 60 seconds — zero install
Run a full research → strategy → backtest loop in your browser. No install, no API key, real market data.
Quick Start · Example Prompts · Community · Platforms · vs. other tools
What you get
Live output from openfinclaw deepagent research — one prompt: research → strategy → backtest → metrics.
Example
c19cfe6db2e1OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add core --env OPENFINCLAW_API_KEY=${OPENFINCLAW_API_KEY} -- npx -y @openfinclaw/[email protected]{
"mcpServers": {
"core": {
"command": "npx",
"args": [
"-y",
"@openfinclaw/[email protected]"
],
"env": {
"OPENFINCLAW_API_KEY": "${OPENFINCLAW_API_KEY}"
}
}
}
}Exposed tools (21)
18 read · 3 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
fin_deepagent_backtest_result | read | |
fin_deepagent_backtests | read | |
fin_deepagent_cancel | read | |
fin_deepagent_download_package | read | |
fin_deepagent_health | read | |
fin_deepagent_messages | read | |
fin_deepagent_package_meta | read | |
fin_deepagent_packages | read | |
fin_deepagent_research_finalize | read | |
fin_deepagent_research_poll | read | |
fin_deepagent_research_submit | write | |
fin_deepagent_skills | read | |
fin_deepagent_status | read | |
fin_deepagent_threads | read | |
strategy_fork | read | |
strategy_get_info | read | |
strategy_leaderboard | read | |
strategy_list_local | read | |
strategy_publish | write | |
strategy_publish_verify | write | |
strategy_validate | read |
Trust audit
CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
openfinclaw-cli-0.6.0.tgz
openfinclaw-core-0.6.0.tgz
.test-branch-protection
for (const rel of ["../package.json", "../../package.json"]) {@types/node, vitest
@clack/prompts, @modelcontextprotocol/sdk, zod, typescript
adm-zip, yaml, @types/adm-zip, typescript
- **Do NOT hardcode API keys in test files** — always read from `process.env.OPENFINCLAW_API_KEY`. 同理:快照 / fixture / 日志文件里也不可留真实 key。
For MCP server contexts (where token-by-token rendering isn't supported by most clients), use the three-step submit/poll/finalize tools instead — they return immediately and let the agent poll for pro
Gates applied: no_behavioural_pass, no_license.
c19cfe6db2e1full audit observations/trust-audit/mcp-server/mirror29__openfinclaw.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | c19cfe6db2e1 | CAUTION | B | 87 | first audit |
Questions
What is the OpenFinClaw MCP server?
One-stop quant-trading AI agent — research · strategy · backtest · paper trade from one prompt. Works in Claude Code, Cursor, and 20+ AI agents via MCP. 60-second install with auto Skill registration.
What tools does OpenFinClaw expose?
21 in total: 18 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is OpenFinClaw safe to connect to an agent?
With care. The audit graded it B (87/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does OpenFinClaw need?
It reads OPENFINCLAW_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does OpenFinClaw run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @openfinclaw/core at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (c19cfe6db2e1), read on 2026-10-07. The repository is watched and re-audited when it changes.