Atlas / MCP servers / verygoodplugins / Robinhood

RobinhoodSAFE

mcp/verygoodplugins/robinhood-1

Read-only MCP server for Robinhood portfolio research

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
15 14r · 1w · 0d
Transport
stdio
License
MIT
Stars
39
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://deepwiki.com/verygoodplugins/robinhood-mcp) [](https://badge.fury.io/py/robinhood-mcp) [](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://modelcontextprotocol.io/)

A read-only MCP server for Robinhood portfolio research. Wraps robin_stocks to give AI assistants access to your portfolio data for analysis.

⚠️ Research Tool Only - This server provides read-only access. No trading functionality is exposed.
⚠️ Unofficial API - Uses robin_stocks unofficial API. May break without notice. Use at your own risk.

Demo

Watch the simulated product demo

This demo uses simulated account data and a generic assistant interface. It shows read-only research workflows only; it does not show real credentials, real holdings, professional advice, or trade execution.

What Can You Do With This?

Once connected, you can have natural conversations with Claude about your portfolio:

Portfolio Health Check

"Give me a health check on my portfolio. What's my total value, sector concentration, and any positions that are significantly up or down?"

Claude will pull your positions, calculate sector exposure, identify your best and worst performers, and flag any concentration risks.

Research Before Buying

"I'm thinking about adding to my NVDA position. Show me the fun
Read from source at commit 465023c030a7OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (pypi)
claude mcp add robinhood-mcp -- None robinhood-mcp==0.1.2
03

Exposed tools (15)

14 read · 1 write · 0 destructive.

ToolRiskDescription
robinhood_get_accountsreadList available Robinhood accounts for account_number selection.
robinhood_get_dividendsreadGet all dividend payments received.
robinhood_get_earningsreadGet earnings data for a stock.
robinhood_get_fundamentalsreadGet fundamental data for a stock.
robinhood_get_historicalsreadGet historical price data for a stock.
robinhood_get_newsreadGet recent news articles for a stock.
robinhood_get_options_positionsreadGet all current options positions (read-only).
robinhood_get_order_historywriteGet historical stock order history (executed buys and sells).
robinhood_get_portfolioreadGet current portfolio value and performance metrics.
robinhood_get_positionreadGet one current stock position with a faster single-symbol lookup.
robinhood_get_positionsreadGet all current stock positions with details.
robinhood_get_quotereadGet real-time quote for a stock symbol.
robinhood_get_ratingsreadGet analyst ratings summary for a stock.
robinhood_get_watchlistreadGet stocks in a watchlist.
robinhood_search_symbolsreadSearch for stock symbols by company name or ticker.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.release-please-manifest.json
.release-please-manifest.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
INFOPrompt injection · prompt.persistence · CWE-94, CWE-1427
README.md:308
# Add to crontab -e
Why it matters. instructs the agent to persist itself in the user's environment

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 465023c030a7full audit observations/trust-audit/mcp-server/verygoodplugins__robinhood-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08465023c030a7SAFEB89first audit
06

Questions

What is the Robinhood MCP server?

Read-only MCP server for Robinhood portfolio research

What tools does Robinhood expose?

15 in total: 14 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Robinhood safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Robinhood need?

It reads ROBINHOOD_PASSWORD and ROBINHOOD_TOTP_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Robinhood run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as robinhood-mcp.

How current is this page?

The grade is for one exact copy of the source (465023c030a7), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement