Financial regulatory data from FINRA, SEC, and market providers for AI assistants.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 7 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The finToolsServer MCP server exposes 32 tools, focused primarily on general-purpose capabilities. Its published description reads: "Financial regulatory data from FINRA, SEC, and market providers for AI assistants". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates finToolsServer F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Data-exfiltration parameters" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check finToolsServer's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add finToolsServer to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://ai.fin-discovery.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Search FINRA BrokerCheck for registered individual brokers and financial representatives by name. Returns CRD number, current firm, registration status, and whether the individual has any disclosures
Search FINRA BrokerCheck for broker-dealer firms by name. Returns firm CRD, registration status, city, state, and disclosure flag. Use this tool when: - You need the CRD number for a broker-dealer fir
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: SearchBrokerCheck
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
public API. No API key required. {"$defs":{"BrokerCheckIndiviRecommendationRemove side-channel parameters; constrain tool inputs.
tool: SearchBrokerCheck
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: SearchBrokerCheckFirm
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
public API. No API key required. {"$defs":{"BrokerCheckFirmSeRecommendationRemove side-channel parameters; constrain tool inputs.
tool: SearchBrokerCheckFirm
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetBrokerCheckDetail
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
lete employment history, exam qualifications, licenses held, anRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetBrokerCheckDetail
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: SearchIAPDFirm
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
public API. No API key required. {"$defs":{"IAPDFirmSearchParRecommendationRemove side-channel parameters; constrain tool inputs.
tool: SearchIAPDFirm
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetIAPDFirmDetail
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
public API. No API key required. {"$defs":{"IAPDFirmDetailParRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetIAPDFirmDetail
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: SearchEdgar13F
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
search API. No API key required. {"$defs":{"EdgarFilingSearchRecommendationRemove side-channel parameters; constrain tool inputs.
tool: SearchEdgar13F
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetEdgarCompanyFilings
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ship disclosure history - You need accession numbers to pull spRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetEdgarCompanyFilings
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetTerritoryWealthProfile
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
y a free Census API key (api.census.gov/data/key_signup.html).RecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetTerritoryWealthProfile
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetTickerInfo
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ia yfinance. No API key required. {"$defs":{"TickerInfoParams"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetTickerInfo
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetPriceHistory
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
story Get Price History (OHLCV) Fetch OHLCV (Open, High, Low,RecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetPriceHistory
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetMultiTickerHistory
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
story Get Price History — Multiple Tickers Fetch OHLCV price hRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetMultiTickerHistory
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetOptionsExpirations
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ia yfinance. No API key required. {"$defs":{"OptionsExpirationRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetOptionsExpirations
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetOptionsChain
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ia yfinance. No API key required. {"$defs":{"OptionsChainParamRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetOptionsChain
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetFinancials
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ia yfinance. No API key required. {"$defs":{"FinancialsParams"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetFinancials
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetEarningsHistory
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ry Get Earnings History & Estimates Fetch earnings history (EPRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetEarningsHistory
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetAnalystRatings
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
), and the full history of analyst upgrades and downgrades withRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetAnalystRatings
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetHolders
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ia yfinance. No API key required. {"$defs":{"HoldersParams":{"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetHolders
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetDividendsAndSplits
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Fetch the full history of cash dividends, stock splits, and combinedRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetDividendsAndSplits
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetFundProfile
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ia yfinance. No API key required. {"$defs":{"FundProfileParamsRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetFundProfile
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: LookupTicker
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ia yfinance. No API key required. {"$defs":{"LookupTickerParamRecommendationRemove side-channel parameters; constrain tool inputs.
tool: LookupTicker
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: SearchFundsByCategory
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
search API. No API key required. {"$defs":{"FundCategorySearcRecommendationRemove side-channel parameters; constrain tool inputs.
tool: SearchFundsByCategory
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetFundFees
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
y facts API. No API key required. {"$defs":{"FundFeesParams":{RecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetFundFees
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: Get13FHoldings
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
otable XML). No API key required. {"$defs":{"Holdings13FParamsRecommendationRemove side-channel parameters; constrain tool inputs.
tool: Get13FHoldings
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: SearchIAPDIndividual
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
tates, and exam history. Use this tool when: - You neeRecommendationRemove side-channel parameters; constrain tool inputs.
tool: SearchIAPDIndividual
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetIAPDIndividualDetail
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
te registration history, exam qualifications, employment historRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetIAPDIndividualDetail
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: SearchFredSeries
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Requires FRED_API_KEY environment variable (free at fred.stlouisfed.oRecommendationRemove side-channel parameters; constrain tool inputs.
tool: SearchFredSeries
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetFredSeriesData
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Requires FRED_API_KEY environment variable (free at fred.stlouisfed.oRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetFredSeriesData
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: MapInstrumentIds
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
penFIGI API. No API key required (optional key raises rate limits).RecommendationRemove side-channel parameters; constrain tool inputs.
tool: MapInstrumentIds
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: SearchFigiInstruments
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
penFIGI API. No API key required (optional key raises rate limits).RecommendationRemove side-channel parameters; constrain tool inputs.
tool: SearchFigiInstruments
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: SearchLEI
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
.gleif.org). No API key required. {"$defs":{"LEISearchParams":RecommendationRemove side-channel parameters; constrain tool inputs.
tool: SearchLEI
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetLEIDetail
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
.gleif.org). No API key required. {"$defs":{"LEIDetailParams":RecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetLEIDetail
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: GetAdvisorBenchmarks
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
24). No API key required — data is embedded as curated static rRecommendationRemove side-channel parameters; constrain tool inputs.
tool: GetAdvisorBenchmarks
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: GetEdgarCompanyFilings
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
Find a CIK at: https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany Source: SEC EDGAR data API. No API keyRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Retrieve the full FINRA BrokerCheck profile for one individual using their CRD number. Returns complete employment history, exam qualifications, licenses held, and all disclosure details. Use this too
Search the SEC Investment Adviser Public Disclosure (IAPD) database for registered investment advisor (RIA) firms by name. Returns firm CRD, registration status, AUM, employee count, state, and office
Retrieve the full Form ADV filing detail for one RIA firm by its CRD number. Returns all Form ADV Part 1 fields: client types, advisory activities, fee arrangements, custody information, office locati
Search SEC EDGAR for 13F-HR institutional holdings filings by institution name. Returns filing date, entity name, period of report, and accession number. Any institution managing more than $100M in eq
Retrieve all SEC filings for a company or institution using its CIK (Central Index Key). Returns every filing on record: form type, date, accession number, and description. Useful for tracking all reg
Retrieve US Census American Community Survey (ACS) income and wealth proxy data for a ZIP code or state. Returns median household income, median home value, total household count, and the count and sh
Fetch the full Yahoo Finance profile for a stock, ETF, mutual fund, crypto, or index. Returns name, sector, industry, market cap, P/E ratio, 52-week range, beta, dividend yield, description, and 60+ o
Fetch OHLCV (Open, High, Low, Close, Volume) price history for one ticker. Returns daily, weekly, monthly, or intraday bars over any period. Use this tool when: - You need historical price or volume d
Fetch OHLCV price history for multiple tickers in a single call. Returns a flattened table with columns like 'AAPL_Close', 'SPY_Volume', etc. Use this tool when: - You are comparing performance across
List all available options expiry dates for a ticker. Use this before calling GetOptionsChain to find a valid expiry date. Use this tool when: - You want to know which options contracts exist for a st
Fetch the full options chain (calls and puts) for one expiry date. Returns strike price, bid, ask, last price, implied volatility, open interest, and volume for every contract. Use this tool when: - Y
Fetch income statement, cash flow statement, or balance sheet for a stock. Returns up to 4 years of annual data or 4 quarters of quarterly data, transposed so each row is one reporting period. Use thi
Fetch earnings history (EPS actual vs estimate, surprise %) and upcoming earnings dates with consensus estimates. Also returns forward EPS estimates by quarter and fiscal year. Use this tool when: - Y
Fetch analyst buy/sell/hold consensus ratings, current price targets (low, high, mean, median), and the full history of analyst upgrades and downgrades with firm name, fromGrade, toGrade, and action.
Fetch ownership data for a stock: top institutional holders, mutual fund holders, and recent insider transactions (buys/sells by executives). Use this tool when: - You want to know which institutions
Fetch the full history of cash dividends, stock splits, and combined corporate actions for a ticker. Returns date, amount/ratio for each event. Use this tool when: - You need dividend history or yield
Fetch ETF or mutual fund specific data: top holdings with weight %, sector allocations, expense ratio, bond credit quality ratings, and equity style characteristics. Use this tool when: - You need the
Search for a Yahoo Finance ticker symbol by company name, fund name, or keyword. Returns matching symbols with exchange and asset type. Use this when you have a name but need the ticker symbol. Use th
Search SEC EDGAR for mutual fund and ETF filers by investment category or keyword. Queries N-1A and 485BPOS (and N-2 for closed-end) prospectus filings. Returns entity name, CIK, form type, and filing
Retrieve expense ratios and fee breakdown for a mutual fund or ETF using its SEC CIK. Reads structured XBRL data filed with prospectuses using the SEC Risk/Return (rr:) taxonomy. Returns: - net_expens
Fetch and parse the complete equity holdings table from a specific SEC 13F-HR filing. Any institution managing more than $100M in US equities must file quarterly — this reveals their exact portfolio p
Search SEC IAPD (Investment Adviser Public Disclosure) for individual investment advisor representatives (IARs) by name. Returns CRD number, current employer, registration states, and exam history. Us
Retrieve the full SEC IAPD profile for one individual investment advisor representative using their CRD number. Returns complete registration history, exam qualifications, employment history, and any
Search the Federal Reserve Bank of St. Louis FRED database for economic data series by keyword. Returns series ID, title, frequency, units, seasonal adjustment, and date range. Use this tool when: - Y
Fetch time-series observation data from FRED for a specific economic series. Returns date + value pairs with series metadata (title, units, frequency). Use SearchFredSeries first if you don't know the
Map financial instrument identifiers between different ID systems using Bloomberg's OpenFIGI service. Converts between ticker symbols, ISINs, CUSIPs, and FIGIs in a single call. Use this tool when: -
Search Bloomberg OpenFIGI for financial instruments by name or keyword. Returns FIGI, ticker, exchange, security type, and composite FIGI for each matching instrument. Use this tool when: - You know t
Search the Global Legal Entity Identifier Foundation (GLEIF) database for Legal Entity Identifiers (LEIs) by entity name. Returns the 20-character LEI code, legal name, registration status, legal addr
Retrieve the full GLEIF LEI record for one legal entity using its 20-character LEI code. Returns legal name, registration status, legal address, headquarters address, managing LOU, and renewal dates.
Return Kitces Research advisor practice benchmark data for independent and RIA-affiliated financial advisors. Covers median and top-quartile metrics across five categories: - revenue: revenue per clie