MCP Risk

Directory / server

ai.ohmyfin/banking-intelligence

This directory entry reports an automated security scan of ai.ohmyfin/banking-intelligence, scanned 2026-07-28. Trust grade F rates provenance, transport, known vulnerabilities and instruction integrity; capability risk is reported separately, not folded into the grade.

registry.modelcontextprotocol.io, scanned 2026-07-28, tool surface via remote-tools-list

F 54/100 permalink

Automated checks

StatusCheckPolicyResult
PASS Listed on the official MCP registry §1.1
Listed on registry.modelcontextprotocol.io as ai.ohmyfin/banking-intelligence. 1 finding
  • Registry entry: ai.ohmyfin/banking-intelligence
WARN Source repository is public and maintained §1.2

No public source repository could be identified for this server.

INFO Published package is consistent and attested §1.3

No published package associated with this server (remote-only or non-npm/PyPI source).

PASS Tool surface is inspectable and proportionate §2.1–§2.4
33 tool(s) enumerated; no high-risk capability signals. 2 findings
  • Tools exposed: 33
  • Detected capabilities: none
PASS HTTPS-only endpoint §3.1
Endpoint uses HTTPS. 1 finding
  • Endpoint: https://mcp.ohmyfin.ai/mcp
UNVERIFIABLE Authentication required §3.2

Endpoint rejected the probe (HTTP 400); whether it requires authentication could not be determined.

WARN OAuth protected-resource metadata published §3.3
No protected-resource metadata found - clients cannot discover the authorization server per spec. 1 finding
  • Checked: https://mcp.ohmyfin.ai/.well-known/oauth-protected-resource
INFO No known vulnerabilities (OSV.dev) §4.1

No package to query (remote-only server).

FAIL Server-supplied instructions free of poisoning indicators §5.1–§5.4
7 suspicious indicator(s) found in server-supplied instructions, tool descriptions, or schemas. 7 findings
  • gpi_status_codes description: oversized: 2064 chars (limit 2048)
  • settlement_eta description: oversized: 3578 chars (limit 2048)
  • track_payment description: oversized: 5182 chars (limit 2048)
  • ssi_lookup description: oversized: 3361 chars (limit 2048)
  • fx_timing_advisor: concealment directive: do NOT tell the user
  • track_payment: imperative to the model: you MUST first
  • ssi_lookup: concealment directive: do NOT tell the user
What this grade covers
  • Provenance & supply-chain integrity (§1)
  • Tool surface & capability risk (§2)
  • Transport & authentication (§3)
  • Known CVEs via OSV.dev (§4)
  • Instruction/tool poisoning patterns (§5)

Limitations: pattern-based only (no semantic injection detection), static npm analysis (live server instructions not retrieved for package-only scans), single-server scope (no cross-server toxic flow analysis). See the full policy.

Methodology: MCP Server Security Policy. Unfamiliar term? See the glossary.