13FLOW
REMOTE · 13FLOW.EU · SCANNED AUG 3
Source-linked SEC 13F research, quality checks, watchlists and audit trails for agents.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security83
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability78
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 827 tokens (~37/item across 22 items; 13 tools + 9 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage76
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 16% of tool parameters carry a description.Partial
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · 13flow.eu
claude mcp add --transport http bluetouff-13flow https://13flow.eu/api/mcp
[mcp_servers.bluetouff-13flow] url = "https://13flow.eu/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"bluetouff-13flow": {
"type": "remote",
"url": "https://13flow.eu/api/mcp",
"enabled": true
}
}
} openclaw mcp add bluetouff-13flow --url https://13flow.eu/api/mcp --transport streamable-http
mcp_servers:
bluetouff-13flow:
url: "https://13flow.eu/api/mcp" {
"mcpServers": {
"bluetouff-13flow": {
"type": "http",
"url": "https://13flow.eu/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 20 to 23. That category is still filling its 30-day observation window: 6 days of observed history at the previous scan, 7 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +5
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 67
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://13flow.eu/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=13flow.eu | CN=YE1,O=Let's Encrypt,C=US | 6 Jun 2026 | 4 Sept 2026 | ECDSA 256 | ECDSA-SHA384 | 5602981febe5c97797eadc2ea24897c8456 |
| SANs: 13flow.eu, www.13flow.eu | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
DNSSEC secure
Validation of 13flow.eu. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| eu. | present | 35926 | 8 | Verified |
| 13flow.eu. | present | 159 | 13 | Verified |
| 13flow.eu. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | SAMEORIGIN |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(), microphone=(), camera=() |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://13flow.eu/api/mcp | Verified | 200 | |
| http (plaintext) | http://13flow.eu/api/mcp | HTTPS enforced | 301 | https://13flow.eu/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
discover_watchlist Discover watchlist candidates ~117
Rank trusted 13F watchlist candidates with explicit filters. Scores are ordinal research screens, not forecasts.
| Name | Type | Req | Description |
|---|---|---|---|
| actions | array | — | — |
| exclude_mega_cap | boolean | — | — |
| include_quality_details | boolean | — | — |
| limit | integer | — | — |
| max_13f_value_usd | number | — | — |
| min_buyers | integer | — | — |
| min_holders | integer | — | — |
| min_score | number | — | — |
| movement_limit | integer | — | — |
| moves | array | — | — |
Structured output declared, but exposes no named fields.
No examples provided.
get_agent_stats Get agent statistics ~51
Return aggregate 7/30-day MCP usage, fixed client families, tool mix and reliability. Initializations are not unique users; no IP, user-agent, version, arguments, prompts or responses are stored.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
get_confluence_methodology Get Confluence methodology ~28
Return the frozen Confluence v1 methodology contract, including proof boundary and validation requirements.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
get_confluence_signals Get Confluence signals ~57
Return public cached Confluence v1 signals. Scores are ordinal heuristic ranks, not probabilities.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | Maximum signals returned by the public API when supported. |
| window | integer | — | Confluence window in days. |
Structured output declared, but exposes no named fields.
No examples provided.
get_data_quality Get data quality ~40
Return public read-only data-quality warnings. These are review signals, never automatic corrections.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | — |
| threshold | number | — | — |
Structured output declared, but exposes no named fields.
No examples provided.
get_fund Get fund evidence ~72
Get a bounded public fund portfolio by SEC CIK, including filing metadata, positions, moves and history counts.
| Name | Type | Req | Description |
|---|---|---|---|
| cik | string | yes | SEC CIK, with or without leading zeroes. |
| history_limit | integer | — | — |
| move_limit | integer | — | — |
| position_limit | integer | — | — |
Structured output declared, but exposes no named fields.
No examples provided.
get_live_status Get live status ~41
Return verifiable public state: LIVE/DEMO/DEGRADED, commit, generated_at, data_as_of, 13F period and coverage.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| git_sha | string | — | — |
| public_state | string | — | — |
| source | string | — | — |
No examples provided.
get_product_status Get product status ~28
Return go-to-market readiness, sellable boundaries, validation status and blocked full-quant artifact.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
get_research_readiness Get research readiness ~28
Return the current research, validation, data-quality and operator-review boundary without commercial claims.
Input schema present but exposes no named parameters.
Structured output declared, but exposes no named fields.
No examples provided.
get_signal_history Get signal history ~42
Read append-only Confluence signal revisions for audit and replay.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | — |
| ticker | string | — | — |
| window | integer | — | — |
Structured output declared, but exposes no named fields.
No examples provided.
get_stock Get ticker flow evidence ~64
Get bounded current 13F holders, quarter moves, quality warnings and ordinal research score for one ticker.
| Name | Type | Req | Description |
|---|---|---|---|
| holder_limit | integer | — | — |
| include_quality_details | boolean | — | — |
| movement_limit | integer | — | — |
| ticker | string | yes | US ticker symbol. |
Structured output declared, but exposes no named fields.
No examples provided.
list_funds List tracked funds ~59
Search and page through compact tracked 13F manager summaries. Use get_fund for positions and moves.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | — | — |
| offset | integer | — | — |
| query | string | — | Optional label, manager or CIK substring. |
| Name | Type | Req | Description |
|---|---|---|---|
| funds | array | yes | — |
| returned | number | yes | — |
| total | number | yes | — |
No examples provided.
preview_watchlist Preview a ticker watchlist ~60
Evaluate 1 to 25 tickers against trusted 13F flow, quality gates and explainable watch/monitor/block triggers.
| Name | Type | Req | Description |
|---|---|---|---|
| include_quality_details | boolean | — | — |
| movement_limit | integer | — | — |
| tickers | array | yes | — |
Structured output declared, but exposes no named fields.
No examples provided.