← Index

three.ws Portfolio

io.github.nirholas/portfolio-mcp·v0.1.0·Other

An agent's trading state — portfolio value, PnL, live balances, trade feed, and signed transfers.

Trust verdict · v1 advisory · method
NOT YET SCREENEDno verdict on file

Verdict not yet evaluated for this tool. The semantic screen takes adversarial cases first; coverage rolls out as the corpus expands (15/150 labels to graduation). The deterministic conformance probe is built but has not yet run on the public corpus, so a recorded verdict here is REVIEW or UNVERIFIED, never a clearing ALLOW. Until a verdict is recorded, an agent should treat this tool as not-yet-cleared and fall back to its own checks. Method: the eval, four-state verdict, honest limits.

Own this server? Screen its description →

Environment variables
THREE_WS_BASE

Base URL of the three.ws API that serves the portfolio + trades endpoints. Override only when self-hosting or targeting a preview deployment.

THREE_WS_TIMEOUT_MS

Per-request timeout in milliseconds for the live three.ws API reads.

THREE_WS_SESSION
secret

Your three.ws session token (the value of the `__Host-sid` cookie from a signed-in browser). Required for the account-scoped reads — get_portfolio_summary, get_portfolio_history, get_portfolio_asset — which return data for the agents YOU own. The public trade feed and on-chain balance reads do not need it. Treat like a password.

SOLANA_RPC_URL

Solana mainnet RPC endpoint used by get_wallet_balances and send_transfer. Defaults to https://api.mainnet-beta.solana.com — bring your own (Helius / QuickNode / Triton) for production traffic.

SOLANA_SECRET_KEY
requiredsecret

Base58-encoded Solana secret key for the wallet that send_transfer signs from. REQUIRED for send_transfer (the only write tool); a per-call `secret` arg overrides it. Not needed for any read tool. Treat like cash.

MAX_SOL_PER_TX

Per-transaction spend cap in SOL for native SOL transfers via send_transfer. Bounds the blast radius of a leaked key or an injected argument.

RECIPIENT_ALLOWLIST

Optional comma-separated base58 pubkeys. When set, send_transfer refuses any recipient not in the list.

REQUIRE_CONFIRM

When on (default), send_transfer refuses until re-issued with confirm:true. Set 0/false to disable the gate.

MCP quality score · maturity, not trust · methodology
freshness
25
completeness
25
installability
25
documentation
15
stability
5
Alternatives in Other