Financial market analysis server for Indian stock market with tools for price fetching, sentiment analysis, signal generation, options chain analysis, portfolio management, and market scanning
This is a custom Express-based HTTP server masquerading as an MCP server, not an actual MCP implementation. Critical structural problems: (1) No MCP protocol implementation detected, no JSON-RPC transport layer, no tool registration via MCP spec, no resource/prompt/logging handlers. (2) Tool definitions are implicit in Express routes, not formally registered with MCP tool schemas. (3) Descriptions are present but minimal (mostly 50-100 chars). (4) Input schemas are completely absent from the MCP perspective, parameters are passed via URL path params and JSON body, not JSON Schema. (5) No output schemas documented. (6) Error handling is generic HTTP status codes, not MCP-style error recovery guidance. (7) Security concerns: MongoDB credentials appear in comments (config/db.js line 1), no API key validation, no rate limiting, no audit logging. (8) No tool composition, 10 separate financial analysis tools with no clear orchestration or data flow between them. The server functions as a REST API for stock market data, not as an MCP server that can be plugged into an LLM or agentic framework.
Analyze sentiment for a stock symbol based on news headlines
Calculate Black-Scholes option Greeks (delta, gamma, theta, vega) for option pricing
Detect unusual activity in options market (high volume spikes) for a given symbol
Generate buy/sell/hold signal based on RSI and MACD technical indicators
Fetch live stock price data for a given symbol
Retrieve options chain data for a given symbol with call and put options at various strike prices
Retrieve sector performance heatmap data showing percentage changes for major sectors
Not an MCP server, no MCP protocol implementation detected. Server is a bare Express REST API without JSON-RPC transport, tool registry, or MCP spec compliance.
No JSON Schema input definitions. Tools have no formal parameter schemas, parameters are passed via URL paths and query strings without type validation.
No output schemas documented. LLMs cannot predict response structure, making composition and chaining error-prone.
Destructive tool (place_trade) lacks confirmation/dry-run step and does not warn LLM of irreversible consequences in description.
Tool descriptions are minimal (40-100 chars) and lack guidance on when to call them or how they differ from similar tools.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | F | 26 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 27 | - | v1 |
Execute a trade order for a given symbol, quantity, and side (BUY/SELL)
Calculate portfolio profit and loss based on current positions and live prices
Scan predefined symbols (RELIANCE, TCS, INFY, HDFCBANK, ICICIBANK) and return those with BUY signals
Parameter naming is inconsistent: 'S', 'K', 'T', 'r', 'sigma' (mathematical notation) vs human-readable names. Rubric requires suffixes like '_price', '_rate', '_volatility'.
Generic/vague tool names: 'scan_market' (should be 'scan_for_buy_signals'), 'process'-style operations conflict with rubric guidance on specific verb_noun naming.
No error recovery guidance. Error responses are generic HTTP status codes without recovery hints (e.g., 'Invalid symbol. Try scan_market() to see available symbols.').
Security: MongoDB credentials leaked in comments (config/db.js). No input validation, rate limiting, or audit logging. Agents can call place_trade without permission checks.
Hardcoded/synthetic data in responses (get_options_chain returns Math.random() for OI/volume; get_sector_heatmap returns fixed JSON). Agents cannot rely on real market data.
No pagination or result limits. scan_market and portfolio_pnl could return unbounded results, risking context window exhaustion.
Tools do not return IDs/references needed for chaining. E.g., place_trade returns order_id but other tools do not accept it, breaking composition.