mrkeyoor.com_
Sun 20 Sept 15:51 UTC
AI Toolsevaluationupdated 20 Sept 2026

financial-services review

Anthropic's Financial Services repository is a collection of Claude plugins and managed-agent templates for banking, research, fund operations, and onboarding work. It supplies prompts, skills, commands, and data connectors that turn source documents into draft models, memos, reconciliations, and review packs for a qualified professional to check.

Verdict

Our Financial Services run installed 35 packages in 7 seconds and built in 1 second, but it had no test target for the finance logic a firm would depend on. Use it as an editable reference library if your team already has Claude, licensed data, and a control process that independently checks every model and memo. Do not treat the included validators or connector catalog as ready for unsupervised financial work.

We ran it

Lab card: what happened when we ran financial-servicesScreenshot of financial-services (github.com/anthropics/financial-services)
Install✓ · 7s35 packages · 37 MB
Build✓ · 1s
Testsn/ano test script
Known vulns0(pip-audit)
Repo387 files~3,743 lines of source · 2.2 MB · 3 CI workflows

Answers from our run

Does financial-services build from source?

Dependencies installed in 7 seconds (35 packages), and the build succeeded in 1 seconds. We cloned commit fca3cc8 into a clean Debian container with 3 CPUs and no project-specific setup.

Does financial-services have tests you can run?

Not through a standard command: the project exposes no test script or target that our harness could run.

Does financial-services have known vulnerabilities in its dependencies?

pip-audit found none in the dependency tree at the time of our run.

Who should not use financial-services?

Firms seeking an automated investment adviser or transaction system: the README says the agents do not recommend investments, execute trades, bind risk, post to ledgers, or approve onboarding.

What are the alternatives to financial-services?

OpenBB, AI Hedge Fund, LangGraph. Our Financial Services run installed 35 packages in 7 seconds and built in 1 second, but it had no test target for the finance logic a firm would depend on.

Setup3/57-second install; real setup starts with data and access control
Docs4/5Broad workflow and security notes, but no end-to-end sample data
Community4/535,224 stars and September activity, with a noisy issue queue
Maturity2/5No release or test target; open finance and connector defects

Who it’s for

Financial institutions already using Claude that want editable starting points for common analyst workflows.
Platform teams prepared to connect licensed market data and internal systems through MCP.
Claude Code or Cowork users who want packaged finance skills such as DCF, comps, earnings review, and ledger reconciliation.
Engineering and control teams that will test every calculation and keep approval outside the agent.

Who it’s NOT for

Firms seeking an automated investment adviser or transaction system: the README says the agents do not recommend investments, execute trades, bind risk, post to ledgers, or approve onboarding.
Evaluators who need bundled sample data: open issue 267 says users currently have to provide their own sources before they can try complete workflows.
Teams expecting every connector to load untouched at the measured commit: issue 355 reports invalid JSON that prevents all 12 core MCP connectors from registering.
Anyone willing to trust generated valuation work without recalculation: open issues 337, 340, and 342 document a WACC check that can return PASS incorrectly, net-debt weighting errors, and basis points inflated by a billion.

Setup reality

Our sandbox installed 35 Python packages in 7 seconds and used 37 MB on disk. The build succeeded in 1 second. There was no tests script or target, so we skipped tests rather than claiming a pass. Pip-audit found 0 known vulnerabilities.

Useful workflows need more than the local install. Managed agents require an Anthropic API key and your own workflow engine. The 12 listed MCP providers may require separate subscriptions or API keys, while reconciliation and onboarding depend on firm systems exposed with suitably narrow access.

The repository is mostly markdown, YAML, JSON, and small Python helpers, so its 387 files are easy to inspect. The harder work is validating finance logic, fixing or pinning manifests, mapping permissions, and keeping every draft behind professional sign-off.

Ten agents produce drafts, not approved financial work

Anthropic packages 10 named workflows, including pitch books, earnings reviews, DCF and LBO models, GL reconciliation, KYC screening, and fund reporting. You can install them as Cowork or Claude Code plugins, or deploy the same prompts and skills through the Managed Agents API. That shared source is useful because an analyst can try a workflow interactively while a platform team wraps it in a controlled service. The repository is Apache-2.0 licensed, so firms can inspect and adapt the instructions.

The boundary matters more than the breadth. The README says these agents draft work for professional review. They do not make investment recommendations, execute transactions, post to a ledger, or approve onboarding. A GL template, for example, gives the document reader only Read and Grep access, caps and validates its JSON output, and keeps the report writer away from outsider files. Ledger adjustments still require approval outside the agent. Those are sensible defaults, but each firm must preserve them while replacing connectors and prompts.

The 7-second install hides the integration job

Our sandbox installed 35 Python packages in 7 seconds and occupied 37 MB. That makes the checkout cheap to inspect, but installation is the smallest part of adoption. Managed deployment needs an Anthropic API key, a workflow engine to handle events, and firm-owned endpoints for jobs such as GL reconciliation. The core plugin lists 12 MCP providers, including FactSet, Morningstar, PitchBook, LSEG, Box, and S&P Global. Several require their own subscription or API key.

There is no complete anonymous dataset in the repository for evaluating a workflow before connecting real sources. Open issue 267 asks for sample statements, CSV files, reports, and demo cases because users currently provide their own data. That leaves a buyer with two choices: build sanitized fixtures or test against controlled internal data. For financial documents, the first route is safer and easier to repeat. A realistic pilot should include planted errors, permission failures, stale records, and adversarial text, not just a clean happy-path workbook.

What happened when we ran it

We cloned commit fca3cc8 into an unprivileged Debian container with 3 CPUs and 8 GB of RAM. The install succeeded in 7 seconds, adding 35 packages and using 37 MB on disk. The build completed in 1 second. Pip-audit reported 0 known vulnerabilities. Those results say the repository's Python tooling is easy to provision in a fresh container. They do not measure Claude output quality, connector authentication, Excel correctness, or the cost of the external data services.

The checkout contained 387 files, about 3,743 lines of source, and 3 CI workflow files. It had no Dockerfile or tests directory. More important, there was no tests script or target, so our harness skipped tests. A skipped test step is different from a passing suite. For a repository that includes calculation helpers and validation scripts, the absence leaves adopters responsible for constructing regression cases around their own templates and the financial rules they intend to rely on.

Invalid JSON can disable all 12 core connectors

Open issue 355 reports that the financial-analysis MCP file at the measured commit is malformed: a comma and closing brace are missing around the Egnyte and Box entries. The reported result is blunt. All 12 connectors fail to register, even though the plugin and its skills can still install. That combination can mislead an analyst into debugging credentials for a connector that never loaded. A pilot should parse every JSON manifest before installation and confirm each expected tool appears in the client.

The connector count also makes least-privilege work unavoidable. Research, document storage, market data, and internal ledgers should not share one broad credential merely because their definitions sit in one file. The managed GL example separates untrusted documents, trusted sources, and the one worker allowed to write a report. Use that pattern as a minimum. Each workflow needs an allowlist, schema checks, narrow scopes, output limits, and a human approval point matched to the action it can influence.

A 35% WACC can pass one included validator

Issue 337 reproduces a DCF validator returning PASS for a workbook containing a 35% WACC. According to the report, the code calls a method that the workbook object does not have, catches the resulting exception, and turns the failed check into a warning. Issue 340 separately challenges the skill's use of net debt when weighting WACC. Issue 342 shows a number parser treating the letter in bps as a billion suffix, turning 150 basis points into 150,000,000,000.

These are open reports, not findings from our sandbox test run, and linked fixes were under discussion when we fetched the repository. They still change the buying decision. Finance teams should compare generated formulas with approved methodology, recalculate outputs in independent code, and keep a fixture set with known answers. The repository's own warning already says qualified professionals must verify the work. With no runnable test target in our measured checkout, that warning needs to become an engineering requirement, not a footer.

September activity is high, while releases are absent

GitHub showed 35,224 stars, 209 combined open issues and pull requests, and a last push on September 18, 2026. Several issues and pull requests were updated on September 20, so the project is active. GitHub returned no latest release, however, and the large combined queue contains both substantive fixes and unrelated spam. Pinning a commit is safer than treating the default branch as a versioned product.

Financial Services is most useful as a map of how Anthropic expects controlled finance agents to be assembled. The 10 workflow templates, explicit sign-off boundaries, and split worker permissions save design time. The missing test target, malformed connector manifest, and open calculation defects prevent the same conclusion about production readiness. Start with one read-only workflow, use sanitized fixtures with known answers, and promote it only after your finance and security reviewers can explain every permission and every number.

Alternatives

ProjectWhat it isPick it when
OpenBBAn open financial data platform for analysts, quants, and agent applications.pick this instead when data access, provider normalization, and an analyst-facing research environment matter more than packaged Claude workflows.
AI Hedge Fund gh↗An educational multi-agent finance project that simulates research and portfolio decisions.pick this instead when you want to study a smaller finance-agent example and will not use it for real investment decisions.
LangGraph gh↗A general framework for building stateful agent workflows with explicit control flow.pick this instead when you need to design the agent graph yourself and do not want Anthropic's finance prompts or Claude-specific packaging.

What people are saying

  1. [github-trending] anthropics/financial-services

Sources

  1. Financial Services repository README
  2. Issue 355: malformed MCP manifest disables connectors
  3. Issue 337: WACC validator can return PASS
  4. Issue 342: basis-point parsing defect
  5. Issue 267: request for sample datasets

More ai tools reviews

autoclip · Portable-Local-Studio · json-render · ai-hedge-fund · chinese-novelist-skill · higgsfield · the whole board →