Atlas / MCP servers / mirror29 / OpenFinClaw

OpenFinClawCAUTION

mcp/mirror29/openfinclaw

One-stop quant-trading AI agent — research · strategy · backtest · paper trade from one prompt. Works in Claude Code, Cursor, and 20+ AI agents via MCP. 60-second install with auto Skill registration.

Verdict
CAUTION
Grade
B
Trust score
87 /100
Exposed tools
21 18r · 3w · 0d
Transport
stdio
License
—
Stars
64
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

English | 中文

Your quant research team, in one prompt.

Research · strategy · backtest · paper trade — ship a complete quant workflow from a single natural-language prompt, inside Claude Code, Cursor, and 20+ AI agents.

[](https://www.npmjs.com/package/@openfinclaw/cli) [](https://www.npmjs.com/package/@openfinclaw/cli) [](https://modelcontextprotocol.io) [](LICENSE)

🚀 Try it in 60 seconds — zero install

Run a full research → strategy → backtest loop in your browser. No install, no API key, real market data.

Quick Start · Example Prompts · Community · Platforms · vs. other tools

What you get

Live output from openfinclaw deepagent research — one prompt: research → strategy → backtest → metrics.

Example

Read from source at commit c19cfe6db2e1OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add core --env OPENFINCLAW_API_KEY=${OPENFINCLAW_API_KEY} -- npx -y @openfinclaw/[email protected]
claude-desktop
{
  "mcpServers": {
    "core": {
      "command": "npx",
      "args": [
        "-y",
        "@openfinclaw/[email protected]"
      ],
      "env": {
        "OPENFINCLAW_API_KEY": "${OPENFINCLAW_API_KEY}"
      }
    }
  }
}
03

Exposed tools (21)

18 read · 3 write · 0 destructive.

ToolRiskDescription
fin_deepagent_backtest_resultread
fin_deepagent_backtestsread
fin_deepagent_cancelread
fin_deepagent_download_packageread
fin_deepagent_healthread
fin_deepagent_messagesread
fin_deepagent_package_metaread
fin_deepagent_packagesread
fin_deepagent_research_finalizeread
fin_deepagent_research_pollread
fin_deepagent_research_submitwrite
fin_deepagent_skillsread
fin_deepagent_statusread
fin_deepagent_threadsread
strategy_forkread
strategy_get_inforead
strategy_leaderboardread
strategy_list_localread
strategy_publishwrite
strategy_publish_verifywrite
strategy_validateread
04

Trust audit

CAUTIONgrade B · trust 87/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMInventory / provenance · inv.binary · CWE-1104
openfinclaw-cli-0.6.0.tgz
openfinclaw-cli-0.6.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.binary · CWE-1104
openfinclaw-core-0.6.0.tgz
openfinclaw-core-0.6.0.tgz
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.test-branch-protection
.test-branch-protection
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/cli/src/init.ts:1244
for (const rel of ["../package.json", "../../package.json"]) {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/node, vitest
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/cli/package.json
@clack/prompts, @modelcontextprotocol/sdk, zod, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/core/package.json
adm-zip, yaml, @types/adm-zip, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:163
- **Do NOT hardcode API keys in test files** — always read from `process.env.OPENFINCLAW_API_KEY`. 同理:快照 / fixture / 日志文件里也不可留真实 key。
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
packages/core/README.md:108
For MCP server contexts (where token-by-token rendering isn't supported by most clients), use the three-step submit/poll/finalize tools instead — they return immediately and let the agent poll for pro
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha c19cfe6db2e1full audit observations/trust-audit/mcp-server/mirror29__openfinclaw.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c19cfe6db2e1CAUTIONB87first audit
06

Questions

What is the OpenFinClaw MCP server?

One-stop quant-trading AI agent — research · strategy · backtest · paper trade from one prompt. Works in Claude Code, Cursor, and 20+ AI agents via MCP. 60-second install with auto Skill registration.

What tools does OpenFinClaw expose?

21 in total: 18 read-only, 3 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is OpenFinClaw safe to connect to an agent?

With care. The audit graded it B (87/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does OpenFinClaw need?

It reads OPENFINCLAW_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OpenFinClaw run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @openfinclaw/core at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (c19cfe6db2e1), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement