MCP/Risk

Scan report

ai.ohmyfin/banking-intelligence

remote, scanned 2026-09-09, tool surface via remote-tools-list

This page reports an automated security scan of ai.ohmyfin/banking-intelligence (remote), scanned 2026-09-09. It rates trust (provenance, transport, known vulnerabilities, instruction integrity) as grade F and capability risk (what the tools can do) separately at low. It does not certify the server is safe to connect; it reports what could be checked from outside.

Tool surface changed. This server’s tool schema differs from its previous scan (2026-07-28). Re-review §2 and §5 before continuing to trust it - silent schema changes are the "rug pull" pattern.

Automated checks

StatusCheckPolicyResult
PASS Listed on the official MCP registry §1.1
Listed on registry.modelcontextprotocol.io as ai.ohmyfin/banking-intelligence. 1 finding
  • Registry entry: ai.ohmyfin/banking-intelligence
WARN Source repository is public and maintained §1.2

No public source repository could be identified for this server.

INFO Published package is consistent and attested §1.3

No published package associated with this server (remote-only or non-npm/PyPI source).

PASS Tool surface is inspectable and proportionate §2.1–§2.4
34 tool(s) enumerated; no high-risk capability signals. 2 findings
  • Tools exposed: 34
  • Detected capabilities: none
PASS HTTPS-only endpoint §3.1
Endpoint uses HTTPS. 1 finding
  • Endpoint: https://mcp.ohmyfin.ai/mcp
UNVERIFIABLE Authentication required §3.2

Endpoint rejected the probe (HTTP 400); whether it requires authentication could not be determined.

WARN OAuth protected-resource metadata published §3.3
No protected-resource metadata found - clients cannot discover the authorization server per spec. 1 finding
  • Checked: https://mcp.ohmyfin.ai/.well-known/oauth-protected-resource
INFO No known vulnerabilities (OSV.dev) §4.1

No package to query (remote-only server).

FAIL Server-supplied instructions free of poisoning indicators §5.1–§5.4
14 suspicious indicator(s) found in server-supplied instructions, tool descriptions, or schemas. 14 findings
  • swift_lookup description: oversized: 2762 chars (limit 2048)
  • gpi_status_codes description: oversized: 2064 chars (limit 2048)
  • fx_volatility description: oversized: 2531 chars (limit 2048)
  • settlement_eta description: oversized: 3953 chars (limit 2048)
  • transfer_cost description: oversized: 8363 chars (limit 2048)
  • sanctions_screen description: oversized: 5762 chars (limit 2048)
  • export_controls_screen description: oversized: 2363 chars (limit 2048)
  • track_payment description: oversized: 5822 chars (limit 2048)
  • ssi_lookup description: oversized: 3789 chars (limit 2048)
  • company_search_company description: oversized: 2062 chars (limit 2048)
  • fx_timing_advisor: concealment directive: do NOT tell the user
  • transfer_cost: concealment directive: do not tell a user
  • track_payment: imperative to the model: you MUST first
  • ssi_lookup: concealment directive: do NOT tell the user

Verify manually - the scoring model can’t judge these for you

  • §2.3 - Is the tool surface no broader than the server’s stated purpose requires?
  • §3.4 - For stdio servers: which environment credentials does it read, and are they scoped rather than org-wide tokens?
  • §6.1 - Cross this server’s capabilities with your already-connected servers: any read-capability × send-capability pairs need explicit sign-off.
  • §6.2 - Run the connecting agent with sandboxing and egress controls sized to the combined tool surface, not just this server’s.

Methodology: MCP Server Security Policy. Checks and scoring weights are open source. Unfamiliar term? See the glossary.