A Go-based MCP (Model Context Protocol) server that provides trading platform integration tools with OAuth authentication, supporting stock/market data queries, order placement, and account management.
This HTTP-based MCP server exposes 9 tools for a trading platform. However, it suffers from critical gaps in schema visibility, parameter documentation, and output definition. The tool definitions are inferred from Makefile examples and the Makefile itself rather than visible in actual source code (internal/handler/tool.go snippet is incomplete). No input JSON schemas are visible in the provided code, only Makefile test invocations show parameter examples. Parameter descriptions are present but generic. Output schemas are entirely undocumented. Error handling guidance is absent. The server handles sensitive financial operations (place_order, login) without visible permission checks, secret injection patterns, or dry-run/confirmation mechanisms. This is typical of early-stage tool implementations that prioritize feature completeness over agent-readiness.
Retrieve user holdings/portfolio information
Retrieve market data for a security
Retrieve order history
Retrieve current trading positions
Retrieve user profile information for a trading account
Retrieve trading history
OAuth Login for trading platform with OAuth authorization URL generation and token exchange
No visible input schemas in source code. Tool definitions are inferred from Makefile test invocations only. JSON Schema documents for tool inputs are not present in the provided code snapshot.
Output schemas are entirely undocumented. No tool describes what fields it returns, their types, or structure. LLMs cannot plan downstream tool calls or extract required data (e.g., does get_profile return a user_id for use in subsequent calls?).
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 54 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 26 | - | v1 |
Place a trading order
Search for stock instruments
place_order accepts 15 parameters but lacks clear guidance on mutual exclusivity, defaults, and constraints. E.g., is 'price' required for MARKET orders? What values are valid for 'order_type', 'validity', 'product', 'execution_type'? These should be enums with explicit descriptions.
No error handling guidance. No tool description explains what errors might occur, how to recover, or what the LLM should do next. Critical for financial operations like place_order, failed orders should include retry guidance.
place_order is an IRREVERSIBLE operation (will modify trading account state) but has no dry-run, confirmation, or explicit destructive hint annotation. No warning that this tool should only be invoked after explicit user consent or confirmation.
login tool handles OAuth token exchange but no visible secret injection pattern. If tokens are returned in responses, they risk being logged or echoed to users. No indication of how credentials are stored or rotated.
No visible permission checks or audit logging. The server accepts client_id and platform but does not document whether it validates that the calling agent has authority to trade on that account. Financial operations require strict permission gating.
Parameter 'platform' is used across most tools but its valid values are not enumerated. Makefile examples show 'uat-tradelab', is this the only valid value? Are there prod values? Enum constraint needed.
Tool descriptions are brief (50-70 chars) but lack context on when to use each tool vs. similar ones. E.g., 'Retrieve user holdings/portfolio information' does not explain the difference between holdings, positions, and trades, when should an LLM choose each?
place_order has 15 required parameters but no indication of defaults, mutual exclusivity, or which subsets are valid together. E.g., 'no_of_legs', 'gtt_price', and 'trigger_price' seem conditional on 'execution_type' or 'order_type', not documented.