DalalOS
REMOTE · MCP.DALALOS.IN · SCANNED SEP 20
Indian NSE/BSE research data and mechanically-computed ratios; read-only market tools.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security92
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability62
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 16703 tokens (~278/item across 60 items; 60 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management40
- Stability observed for 12 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage71
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 0% of tool parameters carry a description.Fail
- Structured output schemas are declared (2% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 61 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the DalalOS MCP server?
DalalOS is a hosted endpoint at https://mcp.dalalos.in/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.dalalos.in
claude mcp add --transport http aatharva16-dalalos 'https://mcp.dalalos.in/mcp'
{
"mcpServers": {
"aatharva16-dalalos": {
"url": "https://mcp.dalalos.in/mcp"
}
}
} {
"servers": {
"aatharva16-dalalos": {
"type": "http",
"url": "https://mcp.dalalos.in/mcp"
}
}
} [mcp_servers.aatharva16-dalalos] url = "https://mcp.dalalos.in/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"aatharva16-dalalos": {
"type": "remote",
"url": "https://mcp.dalalos.in/mcp",
"enabled": true
}
}
} openclaw mcp add aatharva16-dalalos --url 'https://mcp.dalalos.in/mcp' --transport streamable-http
mcp_servers:
aatharva16-dalalos:
url: "https://mcp.dalalos.in/mcp" {
"McpServers": {
"aatharva16-dalalos": {
"Transport": "http",
"Url": "https://mcp.dalalos.in/mcp"
}
}
} assistant mcp add aatharva16-dalalos -t streamable-http -u 'https://mcp.dalalos.in/mcp'
{
"mcpServers": {
"aatharva16-dalalos": {
"type": "http",
"url": "https://mcp.dalalos.in/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 19 Sept 26 +1
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 18 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 17 Sept 26 +1
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 16 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 15 Sept 26 +1
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 14 Sept 26 0
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
- 13 Sept 26 +1
- This server's schema is too large to store in full, so we cannot compare its tools day to day functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://mcp.dalalos.in/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=mcp.dalalos.in | CN=ZeroSSL ECC DV SSL CA 2,O=ZeroSSL GmbH,C=AT | 27 Aug 2026 | 25 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 5ca251fad655ff56f45e640873c6ecc3 |
| SANs: mcp.dalalos.in | ||||||
| CN=ZeroSSL ECC DV SSL CA 2,O=ZeroSSL GmbH,C=AT (CA) | CN=Sectigo Public Server Authentication Root E46,O=Sectigo Limited,C=GB | 24 Sept 2025 | 23 Sept 2035 | ECDSA 256 | ECDSA-SHA384 | c4e1c5bb00f0278f347be4f85d63fcca |
| CN=Sectigo Public Server Authentication Root E46,O=Sectigo Limited,C=GB (CA) | CN=USERTrust ECC Certification Authority,O=The USERTRUST Network,L=Jersey City,ST=New Jersey,C=US | 22 Mar 2021 | 18 Jan 2038 | ECDSA 384 | ECDSA-SHA384 | 1a9eafec6de8e19b5c193141b68d90dd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.dalalos.in. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| in. | present | 10094 | 13 | Verified |
| dalalos.in. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer resource_metadata="https://mcp.dalalos.in/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://mcp.dalalos.in/.well-known/oauth-protected-resource" Protected resource metadata
| Document | https://mcp.dalalos.in/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://mcp.dalalos.in/mcp |
| Authorisation server | https://appealing-lyric-32.authkit.app |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.dalalos.in/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.dalalos.in/mcp | HTTPS enforced | 308 | https://mcp.dalalos.in/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
list_index_valuations ~77
List every NSE index name tracked (headline, broad-market, sector/thematic, India VIX). Each entry carries `{index_name, latest_trade_date, latest_close}`. Powers get_index_valuation's `available_indices_hint` and lets you discover NSE's exact index-name spelling before calling it.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_indices ~19
List the market indices for which constituent membership is cached.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_preset_screens ~87
List the fixed, nightly-precomputed preset screens (name/description/cache freshness). Presets are FIXED mechanical filter combinations (never live-queried, never ranked or labelled as a recommendation) — a discovery starting point a caller can further filter via screen_stocks itself. Use run_preset_screen(name) to fetch one preset's actual results.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
ping ~24
DalalOS health check. Returns a success envelope to confirm the server is reachable.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
remove_from_watchlist ~241
Remove one or more stock symbols from the caller's DalalOS watchlist in a single call. Use this when the user says "stop watching X", "remove X from my watchlist", or "clear my watchlist" (call get_watchlist first, then pass every returned symbol here in one call). This is DalalOS's OWN watchlist -- see add_to_watchlist's docstring for why that distinction matters when multiple MCP servers are connected. `symbols` accepts either a list of strings (mirrors `add_to_watchlist`, capped at `watchlist_tool.MAX_WATCHLIST_BATCH`) or a single bare string (kept for one release for backward compatibility with older single-symbol callers). A partial match -- some symbols on the watchlist, some not -- never fails the call: the response reports `{"removed": [...], "not_found": [...]}` so the caller can see exactly which symbols were actually removed. Requires an authenticated caller; see `get_watchlist` for the auth error shape.
| Name | Type | Req | Description |
|---|---|---|---|
| symbols | – | yes | – |
No output schema declared.
No examples provided.
run_preset_screen ~96
Return the last nightly-precomputed result for one registered preset screen. `name` must be one of the names returned by list_preset_screens. A preset that has never been computed yet returns an empty result with reason_code "no_data". Cache-only — this is the stored output of an equivalent screen_stocks(filters=...) call, not a live query.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | – |
No output schema declared.
No examples provided.
screen_by_query ~550
Screen the Indian security universe with one free-form Screener.in-style expression. Reach for this instead of screen_stocks when the ask needs OR, arithmetic between two metrics, or a comparison screen_stocks' fixed `<metric>_min`/`_max` keys cannot express — e.g. `Return on capital employed > 22% AND (Debt to equity < 0.5 OR Interest Coverage Ratio > 8)`. screen_stocks stays the right tool for a plain AND-combined set of range filters. `dialect` picks the vocabulary and is never guessed: "screener" (default) reads Screener.in ratio names in the units Screener DISPLAYS — `> 22%` against a ratio stored as a fraction, market cap in crore — while "dalalos" reads canonical DalalOS metric ids in the units the cache stores. The metric catalogue for both is GET /v1/ratios; an unrecognised name comes back as an explicit error naming the phrase, never a silent substitution. Operators: AND, OR, = != > < >= <=, + - * /, and COALESCE, IF, LEAST, POWER, ABS, SQRT, LOG. Missing values follow SQL three-valued logic: a bare comparison against an unknown value does NOT match, `COALESCE(<metric>, 0) > x` does, and `A > x OR B > y` can still match on the right side alone. Division by zero is a missing value, not an error. Paging is pinned to one published metrics generation. Each response reports it as `pagination.snapshot_id`; pass that value back as `snapshot_id` on the next page. If a metrics refresh published a new generation in between, the call fails with `snapshot_expired` and the current generation rather than mixing rows from two of them — restart from `offset` 0. `sort_by` is a sortable metric id; ordering puts unknown values last and ends with an ISIN tie-break, so pages never duplicate or skip a row. Returns matching securities with the screened metrics — data only, no recommendations.
| Name | Type | Req | Description |
|---|---|---|---|
| columns | – | – | – |
| definitions | – | – | – |
| dialect | string | – | – |
| limit | integer | – | – |
| offset | integer | – | – |
| only_latest_results | boolean | – | – |
| order | string | – | – |
| query | string | yes | – |
| scope | – | – | – |
| snapshot_id | – | – | – |
| sort_by | string | – | – |
Structured output declared, but exposes no named fields.
No examples provided.
screen_stocks ~1,247
Screen the Indian security universe by user-supplied mechanical criteria. All `filters` keys are optional and AND-combined. `sort_by`/`order` order the result set; `limit` (1..100) caps it. Returns matching securities with the screened metrics — data only, no recommendations. An unknown filter key returns a `bad_request` error that lists every accepted key verbatim, so a rejected call is always self-correcting. RANGE filters (take a `_min` and/or `_max` suffix, e.g. `pe_min: 10, pe_max: 20`): market_cap, price, pe, pb, deliv_pct, week52_high, week52_low, turnover, num_trades (quote-level) — deliv_pct is a PERCENTAGE (50 = 50%); week52_high/week52_low are rupee price levels comparable to `price`; turnover is a rupee traded-value, num_trades a count. promoter_pct, pledged_pct — PERCENTAGES (pass 50 for "50%"), from shareholding data. roe, roa, roce, net_margin, dividend_yield, earnings_yield, fcf_yield, ebitda_margin, operating_margin, quarterly_net_margin_delta_yoy — FRACTIONS (pass 0.15 for "15%"). interest_coverage, ev, ev_to_ebitda, ev_to_ebit, price_to_cash_flow, price_to_fcf, debt_to_equity, price_to_sales, piotroski_f_score (0-9) — plain multiples/scores, no unit conversion needed. revenue_growth, net_income_growth, quarterly_revenue_growth_yoy, quarterly_net_income_growth_yoy, return_1d/1w/1m/3m/6m/1y — FRACTIONS (0.20 = 20% growth or return); unlike the margin/yield group above, these may legitimately exceed 1.0 (>100%) for high-growth or multi-bagger names. pct_off_52w_low — derived, FRACTION: (price - week52_low) / week52_low, e.g. `pct_off_52w_low_max=0.05` for "within 5% of its 52-week low". num_shareholders (a count) and promoter/fii/dii/public_holding_change_qoq — PERCENTAGE POINTS between the latest two shareholding filings (50% -> 55% is 5, not 0.10) — plus num_shareholders_change_qoq, a plain count difference. A security with o…
| Name | Type | Req | Description |
|---|---|---|---|
| filters | object | yes | – |
| limit | integer | – | – |
| order | string | – | – |
| sort_by | string | – | – |
No output schema declared.
No examples provided.
search_company_disclosures ~157
Search this company's already cached official filings, page by page. Use after get_stock_events/get_filing_extract when you need historical context, such as a prior commissioning date, original order announcement, customer, project, or tender. This is cache-only: it never downloads a filing or triggers extraction. Results retain a source page and original BSE attachment URL; `coverage` tells you how much page-preserving history is indexed and explicitly reports parsed legacy filings that cannot be searched reliably yet.
| Name | Type | Req | Description |
|---|---|---|---|
| document_types | – | – | – |
| from_date | – | – | – |
| limit | integer | – | – |
| query | string | yes | – |
| search_text | string | yes | – |
| to_date | – | – | – |
No output schema declared.
No examples provided.
search_stocks ~186
Find Indian stocks by company name, NSE symbol, BSE code, or ISIN. Returns matching securities with their ISIN, internal company_id, name, and both exchange codes. Use this first when a ticker is unknown or ambiguous, then pass a returned `nse_symbol` / `isin` / BSE code as the `query` argument to any other per-stock tool. Tolerant matching: a company-name/symbol typo still surfaces a suggestion, a truncated/ partial ISIN or BSE code matches via prefix, and a former/retired name or symbol (e.g. a pre-rename company name) resolves to the security's current identity, with `resolved_via` on the result naming which kind of resolution fired.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| query | string | yes | – |
No output schema declared.
No examples provided.
What is the DalalOS MCP server?
DalalOS is an MCP server listed in the public MCP registry as io.github.aatharva16/dalalos. Indian NSE/BSE research data and mechanically-computed ratios; read-only market tools. This page covers its hosted endpoint (https://mcp.dalalos.in/mcp).
Is the DalalOS MCP server safe to use?
DalalOS scores 79 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the DalalOS MCP server expose?
DalalOS exposes 60 tools: ping, get_filing_extract, get_market_fii_dii_flow, get_stock_fii_flow, get_watchlist, and 55 more. Their descriptions and schemas cost roughly 15,349 tokens of context every time the server is loaded.
Does the DalalOS MCP server require authentication?
Yes. DalalOS asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the DalalOS MCP server still maintained?
DalalOS is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.