Scores X/Twitter finfluencers on the accuracy of their stock calls against actual price movements and the S&P 500.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 28 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The stock-picker MCP server exposes 24 tools, focused primarily on general-purpose capabilities. Its published description reads: "Scores X/Twitter finfluencers on the accuracy of their stock calls against actual price movements and the S&P 500". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates stock-picker F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Cross-tool shadowing" and "Cross-tool shadowing". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check stock-picker's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add stock-picker to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.koalcheck.com/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
★ CORE. Fetch the recent views of specific X analysts/KOLs by handle. The user names the analysts they follow (e.g. ["DeItaone", "unusual_whales"]). Optionally focus on one `ticker`. Returns, per anal
★ CORE. Compare several analysts' takes on ONE ticker and surface the clash. Groups the named analysts into bull / bear / neutral camps and returns their points so you can construct each side's case (
Search X with full operators (e.g. '$AAPL lang:en -is:retweet', 'from:handle'). General-purpose X search with sentiment scoring; use `analyst_views` when the user cares about specific accounts. Summar
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: search_x
A tool description tries to alter the model’s use of another tool.
t scoring; use `analyst_views` when the user cares about specific accounts. SRecommendationDescriptions must describe only their own tool.
tool: score_ticker
A tool description tries to alter the model’s use of another tool.
StockTwits (run analyst_views on your analysts first to fill the analyst leg)RecommendationDescriptions must describe only their own tool.
tool: analyst_profile
A tool description tries to alter the model’s use of another tool.
n fetched once (analyst_views) so we hold their profile signals.RecommendationDescriptions must describe only their own tool.
tool: analyst_track_record
A tool description tries to alter the model’s use of another tool.
e analyst; call analyst_views first to populate, and matured time windows toRecommendationDescriptions must describe only their own tool.
tool: analyst_recent_calls
A tool description tries to alter the model’s use of another tool.
, distinct from analyst_track_record (how ACCURATE they've been) and from a live timRecommendationDescriptions must describe only their own tool.
tool: quote
A tool description tries to alter the model’s use of another tool.
uota. Pair with score_ticker / fundamentals / analyst_track_record for the fRecommendationDescriptions must describe only their own tool.
tool: direction_review_batch
A tool description tries to alter the model’s use of another tool.
on), then call `direction_review_submit`. Repeat until `remaining`=0. Read-only and $0RecommendationDescriptions must describe only their own tool.
tool: direction_review_submit
A tool description tries to alter the model’s use of another tool.
erdicts from a `direction_review_batch`. `verdicts` is a list, one entry per tweet:RecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: analyst_profile
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "analyst_profile"RecommendationScope tools to the minimum needed.
tool: analyst_recent_calls
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "analyst_recent_calls"RecommendationScope tools to the minimum needed.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Blended retail sentiment for a ticker across X, StockTwits, and Reddit. Use this to corroborate (or challenge) an analyst's view with the broader crowd. `sources` defaults to all three.
Recent StockTwits posts for a ticker with author-tagged bull/bear labels.
Tickers currently trending on StockTwits (a retail-attention radar).
WSB retail-attention for a ticker: mention count, rank, and 24h momentum. Backed by ApeWisdom (reliable). A sharp jump in mentions/rank = a retail- attention spike — often a contrarian/risk flag, not
★ COMPOSITE (Pro). One signed score (−100 bearish … +100 bullish) that blends the analysts who called this ticker — each vote WEIGHTED BY THEIR TRACK RECORD (the moat) — with SEC insider buying/sellin
★ SCREENER (Pro). Rank a universe of tickers by the composite score. source: 'analysts' (tickers your followed analysts have called — ranked by who's been RIGHT) | 'trending' (StockTwits + WSB retail-
★ SEC 8-K — recent MATERIAL EVENTS (earnings, exec changes, M&A, restatements). Catalysts that should move or confirm an analyst's thesis, point-in-time by filing date. Item codes are mapped to plain
SEC/FINRA short-sale VOLUME % for a ticker (last few trading days). Heavy short volume = selling pressure or a squeeze setup (direction-ambiguous). This is daily short VOLUME (flow), NOT short INTERES
★ SEC fundamentals — is the company actually growing & profitable? Latest annual revenue + YoY growth, net income, net/gross margin from SEC XBRL (keyless, point-in-time by filing date). Use it to che
★ SEC Form 4 — are company INSIDERS buying or selling this ticker? Open-market purchases/sales by officers, directors, and 10% owners (Section 16), point-in-time and KEYLESS from SEC EDGAR. Corroborat
Most-mentioned tickers on r/wallstreetbets right now (retail-attention radar, via ApeWisdom).
★ ANTI-IMPOSTOR. Is this account the REAL, credible analyst — or a copycat? Returns the account's authenticity signals (verified, followers, account age, post count) and a credibility score (0-100) +
★ MOAT (Pro). How ACCURATE has this analyst been? Scores their past calls against what the stock actually did vs the market (SPY). Resolves the @handle to the analyst's permanent account id (rename-pr
What has this analyst called LATELY? Their most-recent STORED calls — ticker + direction (bullish/bearish) + date + a link to the original post (and a short snippet of it). PURE READ of already-stored
Which analysts called this ticker, and were they right? Lists stored calls on the ticker with each call's benchmark-adjusted outcome at the given horizon. Analytics, not advice.
Stats on the persisted tweet database (the durable, queryable record). Every analyst tweet fetched is stored with timestamp, tickers, sentiment, and media (image/video URLs). This is the backing data
Live price + volume + turnover (换手率) + market cap + basic valuation for a ticker. Returns last price & % change, day open/high/low, volume + 10-day avg volume, turnover_pct (换手率 = volume ÷ shares outs
The honest track-record leaderboard — who has ACTUALLY been right (priced vs SPY). Reads the daily honest board (21d hit-rate, Wilson 95% CI, bull/bear split, cross-regime flag, point-in-time vs SPY).
YOUR membership tier + today's live-fetch quota for THIS connection. Tells you the plan you're authenticated as (free / pro), how many of today's shared live-fetch pulls you've used (real-time search
OPERATOR-ONLY. Serve a batch of analyst tweets whose per-ticker direction needs accurate classification, plus the rubric to classify them by. Candidates = tweets with ≥1 cashtag that have NOT yet been
OPERATOR-ONLY. Persist the host LLM's per-ticker direction verdicts from a `direction_review_batch`. `verdicts` is a list, one entry per tweet: [{"tweet_id": "...", "verdicts": [ {"ticker": "NVDA", "i