io.github.SharpLu/ko-mcp
REMOTE · MCP.KO.IO · SCANNED SEP 22
Real SEC, 13F, insider, congress & macro data your AI agent can cite. Hosted MCP, 24 tools.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security63
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 24 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability76
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2765 tokens (~115/item across 24 items; 24 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage98
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 94% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 24 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 24 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.SharpLu/ko-mcp server?
io.github.SharpLu/ko-mcp is a hosted endpoint at https://mcp.ko.io/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · mcp.ko.io
claude mcp add --transport http sharplu-ko-mcp 'https://mcp.ko.io/mcp'
{
"mcpServers": {
"sharplu-ko-mcp": {
"url": "https://mcp.ko.io/mcp"
}
}
} {
"servers": {
"sharplu-ko-mcp": {
"type": "http",
"url": "https://mcp.ko.io/mcp"
}
}
} [mcp_servers.sharplu-ko-mcp] url = "https://mcp.ko.io/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"sharplu-ko-mcp": {
"type": "remote",
"url": "https://mcp.ko.io/mcp",
"enabled": true
}
}
} openclaw mcp add sharplu-ko-mcp --url 'https://mcp.ko.io/mcp' --transport streamable-http
mcp_servers:
sharplu-ko-mcp:
url: "https://mcp.ko.io/mcp" {
"McpServers": {
"sharplu-ko-mcp": {
"Transport": "http",
"Url": "https://mcp.ko.io/mcp"
}
}
} assistant mcp add sharplu-ko-mcp -t streamable-http -u 'https://mcp.ko.io/mcp'
{
"mcpServers": {
"sharplu-ko-mcp": {
"type": "http",
"url": "https://mcp.ko.io/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 13 Sept 26 0
- Tool “get_congress_trades” rewrote its description, which is the text the model reads security
- “get_economic_indicators” added an optional parameter “limit” cosmetic
- “get_economic_indicators” added an optional parameter “page” cosmetic
- “get_financial_stress” added an optional parameter “limit” cosmetic
- “get_financial_stress” added an optional parameter “page” cosmetic
- “get_ftd_data” added an optional parameter “limit” cosmetic
- “get_ftd_data” added an optional parameter “page” cosmetic
- “get_insider_trades” added an optional parameter “page” cosmetic
- “get_insider_trades” reworded the description of “limit” cosmetic
- “get_congress_trades” dropped the optional parameter “party” cosmetic
- “get_congress_trades” dropped the optional parameter “state” cosmetic
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 10 Aug 26 0
- Tool “search” rewrote its description, which is the text the model reads security
- “list_institutions” reworded the description of “search” cosmetic
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://mcp.ko.io/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=ko.io | CN=WE1,O=Google Trust Services,C=US | 12 Sept 2026 | 11 Dec 2026 | ECDSA 256 | ECDSA-SHA256 | 75f8487b11c301a1333c64923766cfa |
| SANs: ko.io, *.ko.io | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of mcp.ko.io. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| io. | present | 57355 | 8 | Verified |
| ko.io. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| x-content-type-options | nosniff |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://mcp.ko.io/mcp | Verified | 200 | |
| http (plaintext) | http://mcp.ko.io/mcp | HTTPS enforced | 301 | https://mcp.ko.io/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_congress_member ~88
Get detailed trading history of a specific U.S. Congress member. Shows individual trades with transaction types, amounts, and disclosure dates.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| member | string | yes | Member slug (e.g. 'nancy-pelosi', 'dan-crenshaw'). Use get_congress_trades or search to find exact slugs. |
| page | integer | – | – |
No output schema declared.
No examples provided.
get_congress_trades ~273
Search individual stock trades disclosed by U.S. Congress members (House and Senate) under the STOCK Act. Returns a markdown table of transactions: member name, chamber, ticker, buy/sell type, transaction date, disclosure date (the gap between the two reveals reporting delay), dollar amount range, and owner (self/spouse/joint). Use for questions like 'What did Nancy Pelosi trade recently?', 'Which members bought NVDA?', or 'Show the largest Senate trades this quarter'. Filter by chamber, ticker, or member name; sort by traded value, trade count, or recency. For one member's profile and complete trading history, use get_congress_member instead.
| Name | Type | Req | Description |
|---|---|---|---|
| chamber | string | – | Congressional chamber: house, senate, or all (default all) |
| limit | integer | – | Trades per page, 1-50 (default 20) |
| page | integer | – | Page number for pagination (default 1) |
| search | string | – | Full or partial member name, e.g. 'Pelosi' or 'Dan Crenshaw' |
| sort | string | – | Sort order — volume (most traded value), trades (most trades), recent (latest first) |
| ticker | string | – | Stock ticker symbol to filter by, e.g. NVDA or AAPL |
No output schema declared.
No examples provided.
get_crypto_exposure ~75
Get a market-wide summary of institutional exposure to US spot crypto ETFs (Bitcoin ETF complex: IBIT, FBTC, GBTC, etc.) from the latest quarter of SEC 13F filings. Returns total institutional USD held, quarter-over-quarter change, and a per-ETF breakdown (holders, USD, QoQ).
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_crypto_holder ~106
Get one institution's spot crypto-ETF holdings (Bitcoin ETF complex): its per-ETF positions in the latest filed quarter (shares, USD, QoQ change, action) plus its rank among all crypto-ETF holders. Use a CIK number (find it with get_crypto_holders or the search tool).
| Name | Type | Req | Description |
|---|---|---|---|
| institution | string | yes | Institution CIK number (e.g. '1512857' for Brevan Howard) or name (e.g. 'BlackRock'). |
No output schema declared.
No examples provided.
get_crypto_holders ~114
List institutional investors holding US spot crypto ETFs (Bitcoin ETF complex), ranked by total USD held, from the latest quarter of SEC 13F filings. Optionally filter to holders of a specific ETF via the `product` parameter (e.g. 'IBIT').
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Results per page |
| page | integer | – | Page number |
| product | string | – | Filter to holders of a specific spot crypto ETF ticker, e.g. 'IBIT', 'FBTC', 'GBTC'. |
No output schema declared.
No examples provided.
get_economic_indicators ~163
Get U.S. economic indicators from BLS — CPI (inflation), PPI (producer prices), Non-farm Payrolls (employment), Unemployment Rate, JOLTS. Filter by category.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | Category (case-insensitive): cpi/inflation, ppi, nfp/payrolls, unemployment, jolts, or all |
| days | integer | – | Number of days of history (default 365) |
| limit | integer | – | Rows per page, 1-500 (default 100). A long `days` window can hold more rows than one page; the answer says when the page is full and names the next one. |
| page | integer | – | Page number (default 1) |
No output schema declared.
No examples provided.
get_fed_rates ~146
Get daily U.S. policy and money-market interest rates as a markdown table: Effective Fed Funds Rate, SOFR, Prime Rate, and benchmark Treasury yields (3M, 2Y, 10Y, 30Y) per date, newest first. Use for monetary-policy questions like 'Where is the Fed funds rate now?' or 'How has SOFR moved this quarter?', or to compare policy rates against long-end yields for inversion analysis. Covers up to 10 years of daily history. For the full Treasury curve across all maturities, use get_treasury_yields instead.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | Number of days of history (default 30) |
No output schema declared.
No examples provided.
get_financial_stress ~114
Get the OFR Financial Stress Index — a daily indicator of stress in global financial markets. Values above 0 indicate above-average stress.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | Number of days of history (default 365) |
| limit | integer | – | Rows per page, 1-500 (default 100). A long `days` window can hold more rows than one page; the answer says when the page is full and names the next one. |
| page | integer | – | Page number (default 1) |
No output schema declared.
No examples provided.
get_form144_notices ~101
Get SEC Form 144 filings — notices of proposed sale of restricted/controlled securities by insiders. Filed before selling, these signal upcoming insider sales. Complements Form 4 (post-trade) with pre-trade intent.
| Name | Type | Req | Description |
|---|---|---|---|
| insider_cik | string | – | Filter by insider's CIK number |
| limit | integer | – | Max notices to return |
| ticker | string | – | Filter by stock ticker (e.g. 'AAPL') |
No output schema declared.
No examples provided.
get_ftd_data ~136
Get SEC Failures-to-Deliver (FTD) data for a stock. High FTD quantities may indicate naked short selling or settlement issues.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | Number of days of history (default 90) |
| limit | integer | – | Rows per page, 1-500 (default 100). A long `days` window can hold more rows than one page; the answer says when the page is full and names the next one. |
| page | integer | – | Page number (default 1) |
| ticker | string | yes | Stock ticker symbol (e.g. 'GME', 'TSLA') |
No output schema declared.
No examples provided.
get_insider_trades ~116
Get insider/executive stock trades (SEC Form 4) for a company. Shows CEO, CFO, directors, and other officers buying or selling their own company's stock — a key signal for institutional investors.
| Name | Type | Req | Description |
|---|---|---|---|
| executive_cik | string | – | Filter by specific executive CIK (from list_insider_traders) |
| limit | integer | – | Trades per page, 1-200 |
| page | integer | – | Page number |
| ticker | string | yes | Stock ticker symbol (e.g. 'AAPL') |
No output schema declared.
No examples provided.
get_institution_holdings ~123
Get current stock holdings of an institutional investor (hedge fund, mutual fund, pension fund) from their latest SEC 13F filing. Returns top positions with share counts, values, and quarter-over-quarter changes.
| Name | Type | Req | Description |
|---|---|---|---|
| institution | string | yes | Institution CIK number (e.g. '1067983'), slug (e.g. 'berkshire-hathaway'), or name (e.g. 'Berkshire Hathaway') — names are resolved automatically. |
| limit | integer | – | Results per page |
| page | integer | – | Page number |
No output schema declared.
No examples provided.
get_stock_activity ~78
Get institutional buying/selling activity trend for a stock over multiple quarters. Shows how many institutions are buying vs selling, net share changes, and value flows — useful for detecting accumulation or distribution patterns.
| Name | Type | Req | Description |
|---|---|---|---|
| quarters | integer | – | Number of quarters to return (default 8 = 2 years) |
| ticker | string | yes | Stock ticker symbol |
No output schema declared.
No examples provided.
get_stock_financials ~105
Get quarterly or annual financial statements for a company (revenue, net income, EPS, margins, cash flow, debt ratios) from SEC 10-K/10-Q filings.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Number of periods to return (default 8) |
| period_type | string | – | Period type — quarterly (10-Q) or annual (10-K) |
| ticker | string | yes | Stock ticker symbol (e.g. 'AAPL', 'MSFT') |
No output schema declared.
No examples provided.
get_stock_holders ~82
Get top institutional holders of a stock from SEC 13F filings. Shows which hedge funds, mutual funds, and pension funds own the most shares, with quarter-over-quarter changes.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Results per page |
| page | integer | – | Page number |
| ticker | string | yes | Stock ticker symbol (e.g. 'NVDA') |
No output schema declared.
No examples provided.
get_stock_price ~110
Get historical daily stock prices (OHLC). Returns a summary by default; set series=true to get the full daily price series (for backtesting / charting).
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max rows of the daily series to return when series=true. |
| period | string | – | Look-back window |
| series | boolean | – | If true, return the full daily OHLC series (up to `limit` rows) instead of just a summary. |
| ticker | string | yes | Stock ticker symbol |
No output schema declared.
No examples provided.
get_stock_profile ~66
Get a company's profile — sector, market cap, price, P/E ratio, 52-week range, beta, dividend yield, and other key financials.
| Name | Type | Req | Description |
|---|---|---|---|
| ticker | string | yes | Stock ticker symbol (e.g. 'AAPL', 'NVDA', 'MSFT') |
No output schema declared.
No examples provided.
get_treasury_yields ~72
Get U.S. Treasury yield curve data — daily yields for maturities from 1-month to 30-year. Essential for understanding interest rate environment and yield curve shape.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | Days of daily history to return, 1-3650 (default 30 = last month) |
No output schema declared.
No examples provided.
list_insider_traders ~96
List executives/insiders who have recently traded their company stock. Filter by role (CEO only or all executives). Useful for finding notable insider buying/selling activity across the market.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| page | integer | – | – |
| role | string | – | Filter by role (case-insensitive): CEO, executive/officer, or all |
| search | string | – | Search by name or ticker |
No output schema declared.
No examples provided.
list_institutions ~88
List top institutional investors (hedge funds, mutual funds, etc.) tracked in the SEC 13F database. Supports search by name and pagination.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Results per page |
| page | integer | – | Page number |
| search | string | – | Search by institution name, CIK, or manager name (e.g. 'Klarman' -> Baupost) |
No output schema declared.
No examples provided.
search ~118
Search across institutions, stocks, and insider traders in the ko.io SEC database. Institutions match by firm name OR manager name ('Seth Klarman' -> Baupost, 'Ackman' -> Pershing Square; person hits carry matched_person). Use this first when you have a name but need the CIK number, ticker, or slug to use with other tools.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Max results per category |
| query | string | yes | Search query — company name, ticker, person name, or institution name (min 2 characters) |
No output schema declared.
No examples provided.
sec_get_filing_document ~152
Get a source document from a SEC filing, served by ko.io. Returns a ko.io LINK to the rendered document (open in a browser) plus, optionally, an extracted text excerpt. Never returns the whole file — for full content, open the link or request a specific section.
| Name | Type | Req | Description |
|---|---|---|---|
| accession_no | string | yes | Accession number, e.g. '0000320193-23-000106' |
| cik | string | yes | Company CIK number |
| file | string | – | File name within the filing (from sec_get_filing_index). Omit for the primary document. |
| include_excerpt | boolean | – | Include a text excerpt (first ~6000 chars) in the response |
No output schema declared.
No examples provided.
sec_get_filing_index ~87
Enumerate every file in a single SEC filing (primary document, exhibits, images, XBRL, the full .txt submission). Pass a file name from here to sec_get_filing_document.
| Name | Type | Req | Description |
|---|---|---|---|
| accession_no | string | yes | Accession number, e.g. '0000320193-23-000106' |
| cik | string | yes | Company CIK number |
No output schema declared.
No examples provided.
sec_list_filings ~156
List an entity's SEC filings from EDGAR (most recent first), each with its accession number. Provide the company's CIK (use search or get_stock_profile to find it). Returns accession numbers to pass to sec_get_filing_index / sec_get_filing_document.
| Name | Type | Req | Description |
|---|---|---|---|
| cik | string | yes | Company CIK number (e.g. '320193' for Apple) |
| form_type | string | – | Exact SEC form filter, e.g. '10-K', '13F-HR', '8-K' |
| from | string | – | Earliest filing date, ISO YYYY-MM-DD |
| limit | integer | – | Max filings to return |
| to | string | – | Latest filing date, ISO YYYY-MM-DD |
No output schema declared.
No examples provided.
What is the io.github.SharpLu/ko-mcp server?
io.github.SharpLu/ko-mcp is listed in the public MCP registry as io.github.SharpLu/ko-mcp. Real SEC, 13F, insider, congress & macro data your AI agent can cite. Hosted MCP, 24 tools. This page covers its hosted endpoint (https://mcp.ko.io/mcp).
Is the io.github.SharpLu/ko-mcp server safe to use?
io.github.SharpLu/ko-mcp scores 81 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.SharpLu/ko-mcp server expose?
io.github.SharpLu/ko-mcp exposes 24 tools: get_institution_holdings, list_institutions, get_stock_profile, get_stock_holders, get_stock_activity, and 19 more. Their descriptions and schemas cost roughly 2,765 tokens of context every time the server is loaded.
Does the io.github.SharpLu/ko-mcp server require authentication?
No. We connected to io.github.SharpLu/ko-mcp without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the io.github.SharpLu/ko-mcp server still maintained?
io.github.SharpLu/ko-mcp is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.