The13F Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited The13F Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Model Context Protocol server for the13f. Brings institutional 13F intelligence into Claude Desktop, Cursor, VS Code + Continue, and any MCP-compatible host — no HTTP code required on your side.
Research data only. Sourced from publicly disclosed SEC Form 13F filings, which lag quarter-end by up to 45 days. Past institutional positioning does not predict future performance. Nothing here constitutes investment advice. Every tool's response includes a disclaimer field; the host LLM should surface it alongside any analysis it produces.
uvx the13f-mcpOr pip install the13f-mcp if you prefer to manage Python environments yourself. Python 3.11+ required.
Free, no payment, no credit card:
pf13f_ key — shown onceTHE13F_API_KEY (see below)Free tier: 100 read calls per day; quota rolls at UTC midnight. Signal and report tools arrive in later minor versions when paid tiers launch.
Edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%/Claude/claude_desktop_config.json (Windows):
{
"mcpServers": {
"the13f": {
"command": "uvx",
"args": ["the13f-mcp"],
"env": {
"THE13F_API_KEY": "pf13f_..."
}
}
}
}Restart Claude Desktop. The13f tools should appear in the MCP tool list.
Settings → MCP → Add Server. Paste the same JSON block into the "Custom" field.
Settings → experimental.modelContextProtocolServers → add a stdio transport running uvx the13f-mcp with THE13F_API_KEY in env. The key reveal page at <https://the13f.com/developers/signup-success> shows a copy-paste-ready snippet with the key already filled in.
| Tool | What it does |
|---|---|
list_quarters | All quarters with holdings data + the latest quarter |
search_managers | Autocomplete 13F filers by name |
get_manager_holdings | Full positions for a CIK + quarter |
get_manager_holdings_bulk | Up to 25 (cik, quarter) pairs in one call |
list_all_managers | Universe of 8,600+ filers with per-manager summary stats |
find_similar_managers | Match a portfolio against the universe |
get_consensus_portfolio | Most-widely-held securities per quarter |
get_market_regime | Institutional regime snapshot (IIOI composite, state, transition) |
get_sector_flows | Per-sector capital flows and risk posture |
| Version | Tools | Requires |
|---|---|---|
| v0.2.0 | get_security_signals, get_security_signals_bulk, get_portfolio_signals | Standard tier subscription |
| v0.3.0 | generate_manager_report, generate_security_report, generate_sector_report, check_report_status, wait_and_download_report | Standard tier + stored card; two-step confirm |
The free-tier Read tools are enough to explore the data and build prompts against it. Signal and report tools deliberately wait on the paid-tier billing plumbing.
"Pull Berkshire Hathaway's top 20 positions as of Q4 2025 and summarize what grew the most quarter-over-quarter."
"I own AAPL, MSFT, and NVDA equal-weight. Find the 5 institutional managers whose portfolios most closely resemble mine."
"What sector did 13F filers most aggressively reduce last quarter? Show me the top three managers leading the reduction."
The MCP host's LLM picks the right tool, fills in arguments, surfaces the disclaimer, and returns the result as structured JSON.
| Var | Default | What it controls |
|---|---|---|
THE13F_API_KEY | (none) | Your pf13f_ key. Without it, tools return a structured "free signup required" response with a link to the signup page. |
THE13F_API_BASE_URL | https://api.the13f.com | Override for local development against a running copy of the13f's gui_server. |
THE13F_MCP_TIMEOUT | 30 | Per-request HTTP timeout in seconds. Minimum 5. |
Public source: <https://github.com/pickelfintech/the13f-mcp>. This is the snapshot that PyPI, Glama.ai, and the MCP community list point at. The GitHub repo is a push-mirror of the GitLab one at gitlab.com/pickel-fintech/the13f-mcp; GitLab remains the primary and also carries the release CI. Bug reports and PRs are accepted on either side.
MIT — see LICENSE. The hosted api.the13f.com API that this client calls is a separate service. A free API key (100 calls/day) is required; sign up at <https://the13f.com/developers/>.
[email protected] — quote the request_id field returned by any failing tool call for fastest triage.
MIT. See LICENSE. The MCP server source is MIT-licensed; use of the the13f API itself is governed by the Terms of Service at <https://the13f.com/terms.html>.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.