Atlas / MCP servers / elcukro / Bank

BankCAUTION

mcp/elcukro/bank

Give your AI assistant secure, read-only access to your bank accounts. MCP server supporting Plaid, Teller, Enable Banking, and Tink.

Verdict
CAUTION
Grade
B
Trust score
86 /100
Exposed tools
5 5r · 0w · 0d
Transport
stdio
License
MIT
Stars
50
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Give your AI assistant secure, read-only access to your bank accounts.

[](https://www.npmjs.com/package/@bank-mcp/server) [](https://opensource.org/licenses/MIT) [](https://github.com/elcukro/bank-mcp/actions/workflows/ci.yml) [](https://nodejs.org/) [](https://www.typescriptlang.org/)

Most people manage their finances by logging into bank portals, downloading CSVs, and building spreadsheets. bank-mcp eliminates that friction by letting your AI assistant query your bank accounts directly — balances, transactions, spending breakdowns — through natural conversation. It connects to real bank APIs via the Model Context Protocol so any MCP-compatible client (Claude Code, Claude Desktop, and others) can understand your finances.

  • 5 providers, 15,000+ institutions — US and European banks covered
  • Read-only by design — no write access, no transfers, no modifications
  • Works with any MCP client — Claude Code, Claude Desktop, Cursor, and more
  • Pluggable architecture — add your own provider in under 100 lines

Table of Contents

  • Supported Providers
  • Quick Start
  • Client Setup
  • Available Tools
  • Screenshots
  • Architecture
  • Provider Setup Guides
  • Caching
  • Multiple Connections
  • Security
  • Adding a New Provider
  • [Troubleshooting](#tro
Read from source at commit d0d3e71c04c4OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add server -- npx -y @bank-mcp/[email protected]
claude-desktop
{
  "mcpServers": {
    "server": {
      "command": "npx",
      "args": [
        "-y",
        "@bank-mcp/[email protected]"
      ]
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
get_balancereadGet current account balance(s). Returns closing booked balance and expected balance when available.
list_accountsreadList all bank accounts across configured connections. Returns account UIDs, IBANs, names, and currencies.
list_transactionsreadList bank transactions with optional filters. Defaults to last 90 days. Supports date range, amount range, and debit/credit type filtering.
search_transactionsreadFull-text search across transaction descriptions, merchant names, and references. Use for finding specific payments or payees.
spending_summaryreadGroup expenses by merchant or category with totals. Shows where money is being spent. Use groupBy
04

Trust audit

CAUTIONgrade B · trust 86/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (21)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/refresh.ts:209
console.log(`    Token valid for ${mins} more minutes — refreshing anyway...`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/refresh.ts:261
console.log(`    New token expires: ${(conn.config.tokenExpiresAt as string).slice(0, 19)}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/connect/callback-server.ts:59
const url = new URL(req.url || "/", `http://127.0.0.1:${port}`);
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/init/flows/teller.ts:151
const url = new URL(req.url || "/", "http://127.0.0.1");
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/init/flows/teller.ts:171
const callbackUrl = `http://127.0.0.1:${port}/callback`;
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/connect/flows/enable-banking.ts:20
import { generateJwt } from "../../providers/enable-banking/auth.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/connect/flows/enable-banking.ts:21
import { httpFetch } from "../../utils/http.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/connect/flows/enable-banking.ts:488
opts: import("../../utils/http.js").FetchOptions,
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/connect/flows/tink.ts:15
import { httpFetch } from "../../utils/http.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/init/flows/plaid.ts:15
import type { BankAccount } from "../../types.js";
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/plans/2026-02-22-guided-init-plan.md:727
const url = new URL(req.url || "/", `http://127.0.0.1`);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/plans/2026-02-22-guided-init-plan.md:764
const localUrl = `http://127.0.0.1:${port}`;
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@clack/prompts, @modelcontextprotocol/sdk, jsonwebtoken, zod, @types/jsonwebtoken, @types/node, eslint, typescript
Why it matters. 9 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
architecture.png
architecture.png
Why it matters. 6657622 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
bank-mcp.png
bank-mcp.png
Why it matters. 1783170 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
screenshots/3-list-transactions.png
screenshots/3-list-transactions.png
Why it matters. 1163675 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
screenshots/5-transactions-by-category.png
screenshots/5-transactions-by-category.png
Why it matters. 1046556 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
screenshots/6-group-by-merchants.png
screenshots/6-group-by-merchants.png
Why it matters. 1286100 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/plans/2026-02-22-guided-init-plan.md:339
console.log("    3. Production    — Full access (requires Plaid approval)\n");
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/plans/2026-02-22-guided-init-plan.md:638
console.log("    3. Production    — Full access (requires mTLS certificate)\n");
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/plans/2026-02-22-guided-init-design.md:61
6. Serve Teller Connect HTML locally, open browser, capture access token from callback
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha d0d3e71c04c4full audit observations/trust-audit/mcp-server/elcukro__bank.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08d0d3e71c04c4CAUTIONB86first audit
06

Questions

What is the Bank MCP server?

Give your AI assistant secure, read-only access to your bank accounts. MCP server supporting Plaid, Teller, Enable Banking, and Tink.

What tools does Bank expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Bank safe to connect to an agent?

With care. The audit graded it B (86/100) and found 21 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Bank need?

No credential environment variables were found in its source, so it appears to need none.

How does Bank run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @bank-mcp/server at 0.2.1.

How current is this page?

The grade is for one exact copy of the source (d0d3e71c04c4), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement