Wyckoff Trading Agent MCP Server (YoungCan-Wang/WyckoffTradingAgent) is an MCP server listed on the M8ven Trust Index. It scores 70 out of 100, grade C. It declares 15 tools. No publisher has claimed this listing.

C
Limited view
70/100
2 months ago

Wyckoff Trading Agent MCP Server

Provides 10 tools for Wyckoff volume-price analysis across A-shares, Hong Kong, and US stocks, enabling natural language interactions for stock screening, diagnosis, and reporting.

Limited view. Automated analysis covers part of this stack. Findings reflect what we verified. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

Limited view: static analysis for Python is partially covered.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

YoungCan-Wang

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 10 credentials: TUSHARE_TOKEN, TG_BOT_TOKEN, EFFICIENCY_API_KEY, TICKFLOW_API_KEY, RAG_SEMANTIC_API_KEY, SUPABASE_KEY, SUPABASE_ACCESS_TOKEN, SUPABASE_REFRESH_TOKEN, NVIDIA_API_KEY, GEMINI_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configCF_PAGES_COMMIT_SHA
configVITE_APP_VERSION
🔐 secretTUSHARE_TOKEN
configFUNNEL_POOL_MODE
configFUNNEL_POOL_BOARD
configFUNNEL_EXECUTOR_MODE
🔐 secretTG_BOT_TOKEN
configTG_CHAT_ID
configWYCKOFF_HOME
configOPENAI_BASE_URL
🔐 secretEFFICIENCY_API_KEY
configEFFICIENCY_MODEL
configEFFICIENCY_BASE_URL
configFUNNEL_DYNAMIC_POLICY
configFUNNEL_DYNAMIC_POLICY_HORIZON
configTAIL_BUY_CONFIRMED_ONLY_BUY
configSPOT_SNAPSHOT_TTL_SECONDS
configSPOT_SNAPSHOT_TIMEOUT_SECONDS
configSPOT_TURNOVER_MAX_REL_ERR
configDATA_SOURCE_DEBUG
configBAOSTOCK_MAX_SECONDS
configBAOSTOCK_SOCKET_TIMEOUT
configBAOSTOCK_CIRCUIT_THRESHOLD
configAKSHARE_RETRY_TIMES
configAKSHARE_RETRY_SLEEP_SECONDS
configTICKFLOW_DAILY_MAX_COUNT
🔐 secretTICKFLOW_API_KEY
configDATA_SOURCE_DISABLE_AKSHARE
configDATA_SOURCE_DISABLE_TICKFLOW
configDATA_SOURCE_DISABLE_BAOSTOCK
configDATA_SOURCE_DISABLE_EFINANCE
configALLOW_APPROX_TRADE_CALENDAR
configDEFAULT_LLM_PROVIDER
configLITELLM_ENABLED
configRAG_MAX_WORKERS
configRAG_NEWS_LOOKBACK_DAYS
configRAG_SEMANTIC_VETO_ENABLED
configRAG_SEMANTIC_TIMEOUT
🔐 secretRAG_SEMANTIC_API_KEY
configRAG_SEMANTIC_MODEL
configRAG_SEMANTIC_BASE_URL
configRAG_SEMANTIC_PROVIDER
configRAG_VETO_ENABLED
configRAG_NEGATIVE_KEYWORDS
🔐 secretSUPABASE_KEY
configRECOMMENDATION_PRICE_ALLOW_SPOT_FALLBACK
configRECOMMENDATION_TICKFLOW_BATCH_SIZE
configSUPABASE_USER_ID
configTAIL_BUY_TICKFLOW_BATCH_SIZE
configTHEME_RADAR_GDELT_DISABLED
configTICKFLOW_TIMEOUT_SECONDS
configTICKFLOW_MAX_RETRIES
configTICKFLOW_RETRY_BACKOFF_SECONDS
configTICKFLOW_RATE_LIMIT_MAX_SLEEP_SECONDS
configTICKFLOW_KLINE_RATE_LIMIT_PER_MIN
configTICKFLOW_QUOTES_BATCH_SIZE
configTICKFLOW_QUOTES_BATCH_SLEEP
configTICKFLOW_KLINE_BATCH_SIZE
configTICKFLOW_KLINE_BATCH_SLEEP
configTICKFLOW_INTRADAY_BATCH_SIZE
configTICKFLOW_INTRADAY_BATCH_SLEEP
configTICKFLOW_FINANCIAL_BATCH_SIZE
configTICKFLOW_FINANCIAL_BATCH_SLEEP
configTICKFLOW_LOG_VERBOSE
configTICKFLOW_LIMIT_NOTICE_TTL_SECONDS
configTUSHARE_RATE_LIMIT
🔐 secretSUPABASE_ACCESS_TOKEN
🔐 secretSUPABASE_REFRESH_TOKEN
configBACKTEST_BUY_FRICTION_PCT
configBACKTEST_SELL_FRICTION_PCT
configBACKTEST_METRICS_ENGINE
configBACKTEST_WBT_FEE_RATE
configBACKTEST_WBT_N_JOBS
configBACKTEST_PORTFOLIO_STYLES
configBACKTEST_ENTRY_PRICE_FALLBACK
configFUNNEL_AI_SELECTION_MODE
configFUNNEL_FULL_FORMAL_L4_MAX
configBACKTEST_SNAPSHOT_WORKERS
configBACKTEST_US_KLINE_BATCH_SIZE
configBACKTEST_US_KLINE_BATCH_SLEEP
configBACKTEST_US_BENCHMARK
configBACKTEST_US_MAX_SYMBOLS
configGITHUB_EVENT_PATH
configDAILY_JOB_ARTIFACTS_DIR
configFUNNEL_INTRADAY_TAIL_CONFIRMATION
configFUNNEL_TAIL_CONFIRMATION_MAX_SYMBOLS
configFUNNEL_EXTERNAL_CAPITAL_CONTEXT
configFUNNEL_EXTERNAL_CAPITAL_MAX_SYMBOLS
configFUNNEL_EXTERNAL_CAPITAL_TICK_MAX_SYMBOLS
configFUNNEL_EXTERNAL_CAPITAL_TICK_MIN_AMOUNT_YUAN
configMY_PORTFOLIO_STATE
configFEISHU_WEBHOOK_URL
configWECOM_WEBHOOK_URL
configDINGTALK_WEBHOOK_URL
configSTEP3_SKIP_LLM
configDAILY_JOB_SKIP_STEP4
configLOGS_DIR
configTAIL_BUY_PORTFOLIO_ID
configMARKET_FUNNEL_BENCHMARK_SYMBOLS
configMARKET_FUNNEL_SYMBOL_FILE
configGITHUB_STEP_SUMMARY
configMARKET_FUNNEL_WRITE_DB
configPREMARKET_A50_CRASH_PCT
configPREMARKET_A50_RISK_OFF_PCT
configPREMARKET_VIX_CRASH_PCT
configPREMARKET_VIX_CRASH_CLOSE
configPREMARKET_VIX_RISK_OFF_PCT
configPREMARKET_VIX_READY_HOUR_ET
configPREMARKET_VIX_POLL_INTERVAL_SECONDS
configPREMARKET_VIX_MAX_ATTEMPTS
configREVIEW_SPOT_MIN_COVERAGE
configEND_CALENDAR_DAY
configSIGNAL_REGISTRY_HORIZON
configGITHUB_RUN_URL
configSTEP3_REPORT_STYLE
configSTEP3_MAX_AI_INPUT
configSTEP3_DEFAULT_CONTEXT_CAP
configSTEP3_MAX_PER_INDUSTRY
configSTEP3_EMPTY_COMPRESSION_FALLBACK_CAP
configSTEP3_MAX_UPSTREAM_FILL
configSTEP3_ENABLE_COMPRESSION
configSTEP3_ENABLE_RAG_VETO
configSTEP3_RESPECT_UPSTREAM_PRIORITY
configSTEP3_SEND_COMPLIANCE_BRIEF
configSTEP3_REQUIRE_CONFIRMED_OPERATION
configFEISHU_INPUT_PREVIEW_AS_FILE
configSTEP3_INPUT_PREVIEW_PATH
configGITHUB_SERVER_URL
configGITHUB_REPOSITORY
configGITHUB_RUN_ID
configGITHUB_RUN_NUMBER
configSTEP3_LLM_FALLBACK_PROVIDERS
configSTEP4_RECOMMEND_DATE
configSTEP4_ATR_PERIOD
configSTEP4_ATR_MULTIPLIER
configSTEP4_MAX_WORKERS
configSTEP4_BUY_HARD_STOP_ENABLED
configSTEP4_BUY_HARD_STOP_PCT
configSTEP4_BUY_STOP_MODE
configSTEP4_ATR_SLIPPAGE_FACTOR
configSTEP4_PROBE_BUDGET_LIMIT
configSTEP4_ATTACK_BUDGET_LIMIT
configSTEP4_BUY_BLOCK_REGIMES
configSTEP4_CHASE_GAP_PCT_MIN
configSTEP4_CHASE_GAP_PCT_MAX
configSTEP4_CHASE_ATR_MULT_MIN
configSTEP4_CHASE_ATR_MULT_MAX
configSTEP4_MAX_GAP_UP_PCT
configSTEP4_MAX_GAP_UP_ATR_MULT
configSTEP4_MAX_NEW_BUYS_RISK_ON
configSTEP4_MAX_NEW_BUYS_CAUTION
configSTEP4_MAX_NEW_BUYS_NEUTRAL
configSTEP4_MAX_NEW_BUYS_RISK_OFF
configWYCKOFF_STRATEGY_REFLECTION
configTAIL_BUY_TRIM_WEAK_LOSS_PCT
configMONITOR_PORTFOLIO_ID
🔐 secretNVIDIA_API_KEY
configNVIDIA_BASE_URL
configNVIDIA_MODEL_KIMI
configTAIL_BUY_LLM_TOP_N
configTAIL_BUY_TASK_TIMEOUT_MIN
configTAIL_BUY_STYLE
configTAIL_BUY_FETCH_CONCURRENCY
configTAIL_BUY_LLM_CONCURRENCY
configTAIL_BUY_LLM_MIN_RULE_SCORE
configTAIL_BUY_LLM_ALLOWED_RULE_DECISIONS
configTAIL_BUY_INTRADAY_LIMIT_PER_MIN
configTAIL_BUY_MAX_OVER_LIMIT_SYMBOLS
configTAIL_BUY_TICKFLOW_MAX_RETRIES
configTAIL_BUY_INTRADAY_BATCH_SIZE
configTAIL_BUY_HOLDING_HARD_STOP_PCT
configUS_TRACKING_PERFORMANCE_MAX_DATES
configUS_TRACKING_PERFORMANCE_KLINE_COUNT
configFUNNEL_POOL_MANUAL_SYMBOLS
configFUNNEL_POOL_LIMIT_COUNT
🔐 secretGEMINI_API_KEY
configGEMINI_MODEL
configFUNNEL_TRADING_DAYS
configFUNNEL_FETCH_RETRIES
configFUNNEL_RETRY_BASE_DELAY
configFUNNEL_SOCKET_TIMEOUT
configFUNNEL_FETCH_TIMEOUT
configFUNNEL_BATCH_TIMEOUT
configFUNNEL_BATCH_SIZE
configFUNNEL_BATCH_SLEEP
configFUNNEL_MAX_WORKERS
configFUNNEL_BREADTH_MA_WINDOW
configFUNNEL_BREADTH_RISK_OFF_PCT
configFUNNEL_BREADTH_RISK_ON_PCT
configFUNNEL_BREADTH_RISK_ON_DELTA
configFUNNEL_BREADTH_CLIFF_DROP_PCT
configFUNNEL_SMALLCAP_BENCH_CODE
configFUNNEL_CRASH_MAIN_DAY_DROP_PCT
configFUNNEL_CRASH_SMALL_DAY_DROP_PCT
configFUNNEL_CRASH_BREADTH_RATIO_PCT
configFUNNEL_CRASH_BREADTH_DELTA_PCT
configFUNNEL_PANIC_REPAIR_MIN_AVG_AMOUNT_WAN
configFUNNEL_RISK_OFF_MIN_AVG_AMOUNT_WAN
configFUNNEL_RISK_OFF_DEEP_MIN_AVG_AMOUNT_WAN
configFUNNEL_CRASH_MIN_AVG_AMOUNT_WAN
configFUNNEL_PANIC_REPAIR_ENABLE
configFUNNEL_PANIC_REPAIR_MAIN_REBOUND_PCT
configFUNNEL_PANIC_REPAIR_SMALL_REBOUND_PCT
configFUNNEL_EXPORT_FULL_FETCH
configFUNNEL_EXPORT_DIR
configFUNNEL_DEFENSIVE_FORCE_QUOTA
configFUNNEL_CARD_STYLE
configFUNNEL_EVR_POLICY
configFUNNEL_BYPASS_DISPLAY_LIMIT
configFUNNEL_L2_BYPASS_AI_ENABLED
configFUNNEL_L2_BYPASS_AI_CAP
configFUNNEL_ETF_DISPLAY_LIMIT
configFUNNEL_THEME_RADAR_ENABLED
configFUNNEL_THEME_RADAR_LINK_ENABLED
configFUNNEL_THEME_RADAR_PROMOTE_CAP
configFUNNEL_THEME_RADAR_BONUS_MAX
configFUNNEL_THEME_RADAR_MAX_AGE_DAYS
configFUNNEL_STRATEGIC_L2_BYPASS_ENABLED
configFUNNEL_STRATEGIC_L2_BYPASS_AI_CAP
configFUNNEL_STRATEGIC_L2_BYPASS_MIN_THEME_SCORE
configFUNNEL_STRATEGIC_L2_BYPASS_MIN_STOCK_SCORE
configFUNNEL_STRATEGIC_L2_BYPASS_RESCUE_MIN_SCORE
configFUNNEL_ENABLE_TICKFLOW_BATCH
configWYCKOFF_CONFIG_PATH
configWYCKOFF_CONFIG_PROFILE
configFUNNEL_MONEY_FLOW_LOOKBACK
configFUNNEL_MONEY_FLOW_EXPAND_RATIO
configFUNNEL_MONEY_FLOW_CONTRACT_RATIO
configFUNNEL_MONEY_FLOW_DOMINANCE_RATIO
configMARKET_UNIVERSE_DIR
Deployment configuration, supplied by whoever hosts the server. Users are not asked for these.
deploySUPABASE_URL
deploySUPABASE_SERVICE_ROLE_KEY
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

15/15 tools missing one or more hints — query_history (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); search_stock_by_name (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); analyze_stock (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +12 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

12/15 tool handlers declare input schemas (80%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool handlers catch errors

Only 2/15 tool handlers wrap calls in try/catch (13%)

Wrap each tool handler body in try/catch and return a structured error response.

Tool test coverage

Only 1/15 tools referenced in tests (7%)

Write tests that reference each tool by name so every tool has at least one test.

Domain consistency

npm scope @wyckoff doesn't match GitHub owner youngcan-wang

Use the same org name across GitHub, npm, and your homepage so users can verify the publisher.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 6 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/youngcan-wang/wyckofftradingagent)](https://m8ven.ai/mcp/youngcan-wang/wyckofftradingagent)
Shows your grade and updates automatically. Prefer no grade? Append ?variant=verified to the badge URL.
commit: cdcd5e28a8a42725fe3103babcb11a2cc0eb1b8f
code hash: 5825d2d228d95905d3d88a96a49fe773ba6ae0583f5a33e2c4f95e46b6a38547
verified: 6/16/2026, 1:25:58 PM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client