Back to Browse

Canlicapital MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

canlicapital.com backtest validation. A verdict is not admission to anything and is not a forecast.

About

canlicapital.com backtest validation. A verdict is not admission to anything and is not a forecast.

Security Report

4.2
Use Caution4.2High Risk

This is a legitimate MCP server for a quantitative trading platform's validation API. The codebase demonstrates strong security practices with proper authentication, no malicious patterns, and permissions appropriately scoped to its purpose. Minor code quality issues and the presence of bundled third-party HTTP client code do not materially impact security. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue (1 critical, 0 high severity).

4 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-arhancanli-canli-validation-mcp": {
      "args": [
        "-y",
        "canlicapital"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

canlicapital.com

The public site for Canli Capital, and the surface where ALPHAC — a four-sleeve cross-asset quant book — publishes its record while it is still small enough to be embarrassing.

Created and maintained by Arhan Canli for Canli Capital. Development uses reviewed AI-assisted tooling, while project ownership, research decisions, published claims, and release responsibility remain with Arhan Canli. Machine-readable software citation metadata is provided in CITATION.cff.

The engine that produces every number here is open too: github.com/arhancanli/alphac.

Live: canlicapital.com

Build with it: get an API key, connect the MCP server, or contribute a reproducible improvement. If the project is useful, star the repository to help other developers find it.

Current work and verified limitations: persistent goal status.

Why this repo is public

The site's whole claim is "a quant fund proving itself in public before it asks you to trust it." — the tagline in config/brand.js. A site that makes that claim and hides its own source is asking for a trust it hasn't earned. So: this is the source, including the parts that enforce honesty on us.

The load-bearing one is docs/retracted_claims.txt in the engine repo. When a number is withdrawn it goes on a blocklist, and check_retracted_claims.py scans dist/ and public/ for it before each deploy. It cannot be satisfied by deleting the number — a retracted figure must still be quotable inside its own retraction, so a match counts only when the explanation is absent from the surrounding window.

That check exists because the retraction here had already failed twice: a withdrawn DSR of 0.83 stayed on the homepage and in the social-unfurl card for six days after the signed chain formally withdrew it. The pipeline was publishing the correction and the error in the same run.

The gate is now fail-closed for publication. Since 2026-08-19, both live_tick.sh and live_publish.sh run check_retracted_claims.py after regeneration and skip the deploy when it fails. Trading remains outside that blast radius: a publication defect can stop the website from shipping, but cannot place, cancel, or delay an order.

Publication surfaces

surfacewhat it is
index.htmlthe landing: thesis, systems teaser, live record
systems.htmlhow the four sleeves work
research.htmlthe research programme, literature reviews, feasibility protocols
performance.htmlthe methodology and the honest numbers
progress.htmlthe build log
open.htmlproven in the open: the kill log, the signed chain, glass-box artifacts
verify.htmlindependent verification instructions and downloadable evidence
review.htmlthe governed public criticism bench for five flagship papers
foundry.htmlthe fail-closed design and deployment-acceptance status for Foundry
founder.htmlthe ProfilePage that resolves every Arhan Canli authorship claim
methodology.htmlevidence-linked answers to the research methodology questions
research/*.html111 generated technical reports, each with Scholar metadata and BibTeX
research/topics/*.html13 substantive subject and research-stage indexes
measurements/*.html89 generated Dataset pages with explicit claim boundaries
engineering.htmlthe open-source hub: the three repositories, what is hard in them, and a reading path
notes/*.htmlengineering notes: post-mortems, derivations and design arguments
tools/selection-risk.htmlthe Selection Risk Lab: search a series with no edge, watch the deflation kill what you find
tools/breadth.htmlthe Breadth Lab: what a book of N sleeves is worth, and the ceiling no amount of breadth can pass
tools/execution.htmlthe Execution Reality Lab: which execution assumptions are costs, and which only look like costs
tools/backtest-overfitting.htmlprobability of backtest overfitting by Combinatorially Symmetric Cross-Validation, run in the browser on your own matrix
tools.htmlthe index of every browser calculator this project publishes
developers.htmlthe public read API: endpoints, the response envelope, and what each response cannot be used to claim
costs.htmlevery cost that can reach a return, whether the engine charges it, and which way the answer is wrong when it does not
standards/paper-evidence.htmlcanli.paper-evidence.v0, a proposed open standard whose required fields are the ones a performance claim usually omits

public/paper-state.json and public/glassbox/* are written by the engine's publish job, not by hand. They are the machine-readable form of every claim the pages make. Current corpus counts are derived during the build from public/research-index.json, public/glassbox/trial_packet_manifest.json, and the generated measurement directory; the sitemap is generated from the same files rather than maintained separately. The present build contains 327 canonical URLs in the sitemap (all indexable), plus a public noindex evidence page for every incomplete registered trial and one archival HTML paper per registered sleeve. It publishes identity-level packets for all 228 recorded hypotheses, while honestly marking 226 of those packets incomplete.

Build and run

npm install
npm run build      # Vite multi-page build -> dist/
npm run preview    # serve the built dist
npm run dev        # dev server with hot reload

Three.js, GSAP + ScrollTrigger and Lenis are self-hosted — they install from npm and Vite fingerprints them into dist. Nothing is fetched from a CDN at runtime. The build must stay green, and source plus dist must contain zero em dashes (U+2014); both are audited before deploy.

Brand and facts are single-sourced

config/brand.js is the one place names and numbers live. js/shell.js renders the nav and footer from it so every page ships byte-identical chrome, and js/main.js binds data-brand, data-flagship, data-tagline and data-fact nodes from it.

STATS and FACTS are the only numeric claims permitted on the hand-authored marketing surfaces. Generated papers and measurement pages obtain their figures from engine exports and carry their own source paths and claim boundaries. audit-published-numbers.mjs reconciles the shared site-level figures; do not add a number to either layer without binding it to an authoritative artifact.

Not investment advice

Nothing on this site or in this repo is investment advice, an offer, or a solicitation. The record published here is paper trading; the published ALPHAC strategy record includes no funded performance. Simulated and past performance do not indicate future results. See LICENSE: provided "as is", without warranty.

Glass-box platform expansion

The platform direction and quality contract connect the research engine, developer API/MCP and the company-reference collection. The local expansion candidate adds 49 SEC-backed reference pages; it is not a million-page deployment. The search goal is at least 800,000 indexed pages, targeting 1,000,000, recorded in config/search-growth-goal.json. npm run seo:inventory reports built counts separately from actual indexing evidence; the indexed count remains unverified until Search Console evidence is available. --require-indexed-minimum fails while that evidence is missing. npm run seo:capacity tests sitemap transport with synthetic URLs in a temporary directory.

Refresh selected company records explicitly with npm run companies:import -- CIK [CIK ...]. Builds use captured public JSON and original compressed source snapshots, with no network ingestion during publication. The selected latest-filed histories may contain restatements and are not point-in-time backtest data. Public JSON downloads do not extend the validation API's capabilities.

Reviews

No reviews yet

Be the first to review this server!