Local MCP server for portfolio analysis. 27 skills, 103 tools, 15 data adapters, runs in Claude Code/Desktop - no API key required.
- capability exposureinferred+35
- recent driftinferred+12
- tool safetyinferred+14
- trust mitigatorsmixed−3
inferredmixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 15m ago · see ecosystem CVEs →
- A · 9 → C · 58
No known CVEs for this server.
- highdangerous code
dynamic exec: __import__()
- lowexfiltration combo
sensitive read and network capabilities split across this server's tools
analyzed commit 440126c · analyzer v18 · 2h ago
skills & prompt files 30
- skilltusharagg1-aifolimizer-440126c/.claude/skills/adversarial-research/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/auto-rebalance/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/cash-deployment/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/daily-briefing/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/dividend-strategy/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/earnings-analyzer/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/earnings-postmortem/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/employer-stock/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/health-check/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/macro-impact/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/momentum-scanner/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/optimize-allocation/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/pead-tracker/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/perf-optimizer/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/portfolio-health/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/portfolio-review/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/position-review/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/pre-trade-check/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/profile-setup/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/risk-assessment/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/sector-rotation/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/stock-analysis/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/stock-compare/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/tax-loss-review/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/top-trades-today/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/trade-journal/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/trading-desk/SKILL.md
- skilltusharagg1-aifolimizer-440126c/.claude/skills/weekly-mirror/SKILL.md
- agent-rulestusharagg1-aifolimizer-440126c/AGENTS.md
- agent-rulestusharagg1-aifolimizer-440126c/CLAUDE.md
danger signals7
- dynamic code execution__import__()tusharagg1-aifolimizer-440126c/backend/app/services/agent_registry.py:313
mod = __import__(mod_path, fromlist=[fn_name]) - dynamic code execution__import__()tusharagg1-aifolimizer-440126c/backend/scripts/health_check.py:66
__import__(f"app.services.{name}") - suspicious endpointapi.telegram.orgtusharagg1-aifolimizer-440126c/backend/app/services/notifications/telegram.py:24
_TELEGRAM_API = "https://api.telegram.org" - suspicious endpointapi.telegram.orgtusharagg1-aifolimizer-440126c/backend/main.py:89
f"https://api.telegram.org/bot{settings.telegram_bot_token}/sendMessage", - suspicious endpointapi.telegram.orgtusharagg1-aifolimizer-440126c/backend/scripts/mfa_notify.py:33
TG_API = "https://api.telegram.org" - suspicious endpointapi.telegram.orgtusharagg1-aifolimizer-440126c/backend/scripts/send_daily_briefing.py:109
f"https://api.telegram.org/bot{_cfg.telegram_bot_token}/sendMessage", - suspicious endpointapi.telegram.orgtusharagg1-aifolimizer-440126c/backend/scripts/send_telegram.py:25
_API = "https://api.telegram.org"
- recent drift+12 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of tusharagg1.