io.github.koreal6803/finlab-ai
REMOTE · MCP.FINLAB.FINANCE · SCANNED SEP 27
Quantitative trading toolkit with 900+ data columns, backtesting, and 60+ strategy examples.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security46
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 406, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 831 tokens (~138/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 6 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 7 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities60
- Spec-recency check failed: implements MCP spec 2025-06-18; the latest is 2026-07-28. See how to fix → Fail
How do I install the io.github.koreal6803/finlab-ai MCP server?
io.github.koreal6803/finlab-ai is a hosted endpoint at https://mcp.finlab.finance/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.finlab.finance
claude mcp add --transport http koreal6803-finlab-ai 'https://mcp.finlab.finance/mcp'
{
"mcpServers": {
"koreal6803-finlab-ai": {
"url": "https://mcp.finlab.finance/mcp"
}
}
} {
"servers": {
"koreal6803-finlab-ai": {
"type": "http",
"url": "https://mcp.finlab.finance/mcp"
}
}
} [mcp_servers.koreal6803-finlab-ai] url = "https://mcp.finlab.finance/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"koreal6803-finlab-ai": {
"type": "remote",
"url": "https://mcp.finlab.finance/mcp",
"enabled": true
}
}
} openclaw mcp add koreal6803-finlab-ai --url 'https://mcp.finlab.finance/mcp' --transport streamable-http
mcp_servers:
koreal6803-finlab-ai:
url: "https://mcp.finlab.finance/mcp" {
"McpServers": {
"koreal6803-finlab-ai": {
"Transport": "http",
"Url": "https://mcp.finlab.finance/mcp"
}
}
} assistant mcp add koreal6803-finlab-ai -t streamable-http -u 'https://mcp.finlab.finance/mcp'
{
"mcpServers": {
"koreal6803-finlab-ai": {
"type": "http",
"url": "https://mcp.finlab.finance/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 25 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 13 Sept 26 0
- Stability: 0.97 → pass security
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 10 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 77 to 80. That category is still filling its 30-day observation window: 23 days of observed history at the previous scan, 24 at this one. The score rises as the window fills, whether or not the server changes.
- 5 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.
- 3 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 57 to 60. That category is still filling its 30-day observation window: 17 days of observed history at the previous scan, 18 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 27 Sept 2026 · Probed https://mcp.finlab.finance/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=finlab.finance | CN=WE1,O=Google Trust Services,C=US | 19 Sept 2026 | 19 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 7afa71235fdebfef0e6f1c5c46435ad4 |
| SANs: finlab.finance, mcp.finlab.finance, *.mcp.finlab.finance | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.finlab.finance. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| finance. | present | 28624 | 8 | Verified |
| finlab.finance. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.finlab.finance/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.finlab.finance/mcp | Inconclusive | 406 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_data_catalog FinLab 資料庫目錄摘要 ~79
取得 FinLab 量化資料庫的目錄摘要:涵蓋台股與美股的分類數、欄位數、資料列數、年份範圍,以及代表性資料集(股價、月營收、財務指標等)。適合回答「FinLab 有哪些資料」。
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_finlab_docs FinLab Skill 開發文件 ~164
取得 FinLab Skill 的開發文件(與 GitHub koreal6803/finlab-ai main 分支同步,skill 更新後自動生效):不帶參數回傳 SKILL.md 主文件與參考文件清單;帶 doc 參數回傳指定參考文件全文。涵蓋 900+ 資料欄位、sim() 回測 API、60+ 策略範例、因子分析與機器學習等,撰寫 finlab Python 程式前建議先查閱。
| Name | Type | Req | Description |
|---|---|---|---|
| doc | string | – | 參考文件檔名,例如 "dataframe-reference.md"。省略時回傳 SKILL.md 與文件清單。 |
No output schema declared.
No examples provided.
get_stock_evidence 查個股數據實證 ~183
查詢台股個股的每日更新數據實證:基本面體質定位(獲利、估值、籌碼因子百分位)、目前正在觸發的量化訊號與其歷史前瞻報酬統計、估值位階等。例如 symbol="2330" 查台積電。資料來自 FinLab 每日以 finlab 套件計算的真實數據。
| Name | Type | Req | Description |
|---|---|---|---|
| market | string | – | 市場,預設 "tw" 台股;"us" 為美股(覆蓋率較低)。 |
| symbol | string | yes | 台股股票代號字串,例如 "2330"(台積電)、"0050"、"00631L"。保留前導零,不要轉成數字。 |
No output schema declared.
No examples provided.
get_strategy 取得單一策略完整內容 ~89
取得 FinLab 策略庫中單一策略的完整快照:策略說明、真實回測績效與基準比較、以及可直接執行的 finlab Python 程式碼。slug 可先用 list_strategies 查詢。
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | 策略代號(slug),例如由 list_strategies 取得 |
No output schema declared.
No examples provided.
how_to_start FinLab 快速上手 ~82
取得 FinLab 快速上手指南:如何用 AI 輔助流程(Claude cowork / Codex)在自己電腦安裝 FinLab 並跑第一個台股策略真實回測,以及免費線上體驗入口。適合回答「怎麼開始用 FinLab」「怎麼回測台股」。
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_strategies 列出 FinLab 策略庫 ~77
列出 FinLab 公開策略庫中的台股量化策略,含每一檔策略的真實回測績效摘要(CAGR、Sharpe、最大回撤)與基準比較。想看完整策略內容與 Python 程式碼時,請接著呼叫 get_strategy。
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the io.github.koreal6803/finlab-ai MCP server?
io.github.koreal6803/finlab-ai is an MCP server listed in the public MCP registry as io.github.koreal6803/finlab-ai. Quantitative trading toolkit with 900+ data columns, backtesting, and 60+ strategy examples. This page covers its hosted endpoint (https://mcp.finlab.finance/mcp).
Is the io.github.koreal6803/finlab-ai MCP server safe to use?
io.github.koreal6803/finlab-ai scores 72 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.koreal6803/finlab-ai MCP server expose?
io.github.koreal6803/finlab-ai exposes 6 tools: list_strategies, get_strategy, get_stock_evidence, get_data_catalog, get_finlab_docs, how_to_start. Their descriptions and schemas cost roughly 674 tokens of context every time the server is loaded.
Does the io.github.koreal6803/finlab-ai MCP server require authentication?
No. We connected to io.github.koreal6803/finlab-ai without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.koreal6803/finlab-ai MCP server still maintained?
io.github.koreal6803/finlab-ai is still listed as active in the MCP registry. We last reached this channel on 27 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.