Atlas / MCP servers / akutishevsky / LunchMoney

LunchMoneyCAUTION

mcp/akutishevsky/lunchmoney-2

A Model Context Protocol (MCP) server implementation for LunchMoney, providing programmatic access to personal finance management through LunchMoney's API.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
59 32r · 15w · 12d
Transport
stdio
License
MIT
Stars
109
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@akutishevsky/lunchmoney-mcp) [](https://www.npmjs.com/package/@akutishevsky/lunchmoney-mcp) [](https://github.com/akutishevsky/lunchmoney-mcp/releases) [](https://github.com/akutishevsky/lunchmoney-mcp/blob/main/LICENSE) [](https://www.typescriptlang.org/) [](https://lobehub.com/mcp/akutishevsky-lunchmoney-mcp)

A Model Context Protocol (MCP) server implementation for LunchMoney, providing programmatic access to personal finance management through LunchMoney's API. Also available as an MCP Bundle (.mcpb) for easy installation in Claude Desktop.

Heads up — v3.0.0 removes `get_all_crypto`. The crypto tools now use LunchMoney's v2 crypto endpoints, which split manual and synced holdings into separate resources and offer no combined equivalent of v1's GET /crypto. Replace get_all_crypto with get_all_manual_crypto and get_all_synced_crypto, which together return everything it did and more. update_manual_crypto also drops its currency parameter. Nothing outside the crypto domain changed; if you don't use the crypto tools, upgrading from 2.x needs no action. See CHANGELOG.md. If you depend on get_all_crypto, pin @akutishevsky/lunchmoney-mcp@^2.2.0.
Heads up — v2.0.0 is a breaking release. This server now targets LunchMoney's v2 API (https://api.lunchmoney.dev/v2, currently in alpha). It is not backwards-compatible with v1.x of this server: t
Read from source at commit c1f2fd9a3bcfOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add lunchmoney-mcp --env LUNCHMONEY_API_TOKEN=${LUNCHMONEY_API_TOKEN} -- npx -y @akutishevsky/[email protected]
03

Exposed tools (59)

32 read · 15 write · 12 destructive. Blast radius: 12 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_supported_cryptocurrencywrite
attach_file_to_transactionread
create_categorywrite
create_manual_accountwrite
create_manual_cryptowrite
create_tagwrite
create_transaction_groupwrite
create_transactionswrite
delete_account_balance_historydestructive
delete_balance_history_entrydestructive
delete_categorydestructive
delete_crypto_synced_balance_historydestructive
delete_manual_accountdestructive
delete_manual_cryptodestructive
delete_tagdestructive
delete_transactiondestructive
delete_transaction_attachmentdestructive
delete_transaction_groupdestructive
delete_transactions_bulkdestructive
get_account_balance_historyread
get_all_categoriesread
get_all_manual_accountsread
get_all_manual_cryptoread
get_all_plaid_accountsread
get_all_synced_cryptoread
get_all_tagsread
get_balance_historyread
get_budget_settingsread
get_budget_summaryread
get_crypto_synced_balance_historyread
get_recurring_itemsread
get_single_categoryread
get_single_manual_accountread
get_single_manual_cryptoread
get_single_plaid_accountread
get_single_recurring_itemread
get_single_synced_cryptoread
get_single_tagread
get_single_transactionread
get_supported_cryptocurrenciesread
get_synced_crypto_balanceread
get_transaction_attachment_urlread
get_transactionsread
get_userread
refresh_synced_cryptoread
remove_budgetdestructive
split_transactionread
trigger_plaid_fetchwrite
unsplit_transactionread
update_categorywrite
update_deleted_account_detailswrite
update_manual_accountwrite
update_manual_cryptowrite
update_tagwrite
update_transactionwrite
update_transactions_bulkwrite
upsert_account_balance_historyread
upsert_budgetread
upsert_crypto_synced_balance_historyread
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (5)

MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
test/helpers.mjs:36
"-----BEGIN OPENSSH PRIVATE KEY-----\nb3BlbnNzaC1rZXktdjEAAAAA\n-----END OPENSSH PRIVATE KEY-----\n",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_account_balance_history, delete_balance_history_entry, delete_category, delete_crypto_synced_balance_history, delete_manual_account, delete_manual_crypto, delete_tag, delete_transaction, delete
Why it matters. 12 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
test/transactions.tool.test.mjs:93
const key = box.file("outside/id_rsa", FIXTURES.privateKey);
Why it matters. touches a credential store
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @toon-format/toon, zod, @eslint/js, @types/node, eslint, husky, prettier
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:205
[lunchmoney-mcp-cloudflare](https://github.com/bm1549/lunchmoney-mcp-cloudflare) wraps this package as a Cloudflare Worker with Google sign-in and an email allowlist in front of the MCP endpoint. The
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha c1f2fd9a3bcffull audit observations/trust-audit/mcp-server/akutishevsky__lunchmoney-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07c1f2fd9a3bcfCAUTIONB89first audit
06

Questions

What is the LunchMoney MCP server?

A Model Context Protocol (MCP) server implementation for LunchMoney, providing programmatic access to personal finance management through LunchMoney's API.

What tools does LunchMoney expose?

59 in total: 32 read-only, 15 that write, and 12 that can delete or overwrite (delete_account_balance_history, delete_balance_history_entry, delete_category, delete_crypto_synced_balance_history, delete_manual_account). Every one is listed on this page with its risk.

Is LunchMoney safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 12 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does LunchMoney need?

It reads LUNCHMONEY_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does LunchMoney run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @akutishevsky/lunchmoney-mcp at 3.0.0.

How current is this page?

The grade is for one exact copy of the source (c1f2fd9a3bcf), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement