Copilot MoneyBLOCK
MCP server for Copilot Money App - AI powered personal finance queries using local data
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Query and manage your personal finances with AI using local Copilot Money data
[](https://opensource.org/licenses/MIT) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://github.com/ignaciohermosillacornejo/copilot-money-mcp/actions/workflows/test.yml) [](https://codecov.io/gh/ignaciohermosillacornejo/copilot-money-mcp) [](https://glama.ai/mcp/servers/ignaciohermosillacornejo/copilot-money-mcp) [](https://registry.modelcontextprotocol.io/?q=copilot-money-mcp)
Disclaimer
This is an independent, community-driven project and is not affiliated with, endorsed by, or associated with Copilot Money or its parent company in any way. This tool was created by an independent developer to enable AI-powered queries of locally cached data. "Copilot Money" is a trademark of its respective owner.
[!NOTE] Copilot Money has announced an official MCP server (currently in waitlist, read-only). If a first-party, read-only integration suits your needs, you should strongly consider using it instead of this community project. Learn more and join the waitlist at agent.copilot.money. This project remains useful if you need write tools (categorize transactions, manage budgets, edit recurrings, etc.), fully offline cache-mode reads with zero network requests, or simply want
e43f9afe1eb9OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add copilot-money-mcp -- npx -y [email protected]
Exposed tools (51)
34 read · 13 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_transaction_to_recurring | write | Manually link an existing transaction to an existing recurring series. Use this when |
bulk_edit_transactions | write | Apply the SAME edit to MANY transactions in ONE request — Copilot |
create_category | write | Create a new custom category in Copilot Money. Provide name, color_name, |
create_recurring | write | Create a new recurring/subscription item by seeding it from an existing transaction. |
create_tag | write | Create a new user-defined tag for categorizing transactions. Tags appear in the |
create_transaction | write | Create a brand-new manual transaction on an existing account. Requires |
delete_category | destructive | Delete a user-defined category. The category_id can be obtained from get_categories. |
delete_recurring | destructive | Delete a recurring item (subscription/charge). |
delete_tag | destructive | Delete a user-defined tag. The tag_id can be obtained from the tag definitions |
delete_transaction | destructive | **DESTRUCTIVE**: Permanently deletes a transaction from Copilot Money. |
get_accounts | read | Get all accounts with balances, plus summary fields: total_balance (net worth = assets minus liabilities), |
get_accounts_live | read | Get all linked financial accounts (live, GraphQL-backed). Returns balances and metadata. |
get_aggregated_holdings_live | read | Get per-security aggregated holdings (live, GraphQL-backed). One row per security, |
get_balance_history | read | Get daily balance snapshots for accounts over time. Each entry returns current_balance, |
get_balance_history_live | read | Get daily balance history for a single account (live, GraphQL-backed). |
get_budgets | read | Get budgets from Copilot |
get_budgets_live | read | Get budgets from Copilot |
get_cache_info | read | Get information about the local data cache, including the date range of cached transactions |
get_categories | read | Unified category retrieval tool. Supports multiple views: |
get_categories_live | read | Get user categories (live, GraphQL-backed), including each category id, parentId, and a |
get_connection_status | read | Get connection status for all linked financial institutions. |
get_goal_history | read | Get monthly progress snapshots for financial goals. Returns current_amount, |
get_goals | read | Get financial goals from Copilot |
get_holdings | read | Get current investment holdings with position-level detail. Returns ticker, name, |
get_holdings_live | read | Get investment positions with cost-basis metrics (live, GraphQL-backed). |
get_investment_allocation_live | read | Get the portfolio asset-class allocation (live, GraphQL-backed). Returns one row per |
get_investment_balance_live | read | Get your investments-only combined balance (live, GraphQL-backed): |
get_investment_prices | read | Get investment price history for portfolio tracking. Returns one row per |
get_investment_prices_live | read | Get price history for a single security (live, GraphQL-backed). time_frame picks the |
get_investment_splits | read | Get stock split events from the local Firestore cache. Returns one row |
get_monthly_spend_live | read | Get the current month |
get_networth_live | read | Get net-worth-over-time history (live, GraphQL-backed). Returns daily snapshots |
get_recurring_live | read | Get user-confirmed recurring/subscription items (live, GraphQL-backed). |
get_recurring_transactions | read | Identify recurring/subscription charges. Combines two data sources: |
get_tags_live | read | Get all user tags (live, GraphQL-backed). Each row carries |
get_top_movers_live | read | Get the biggest movers across your investment holdings (live, GraphQL-backed). |
get_transactions | read | Reads from the local LevelDB cache, which may lag behind Copilot |
get_transactions_live | read | Read and filter transactions live from Copilot |
get_upcoming_recurrings_live | read | Get the next-due recurring/subscription items — the |
refresh_cache | read | Flush the in-memory live cache by scope. Use when the user explicitly wants fresh data despite TTLs. Does not touch LevelDB (use refresh_database for that). Live-reads mode only. |
refresh_database | read | Refresh the in-memory cache by reloading data from the local Copilot Money database. |
review_transactions | read | Bulk mark transactions as reviewed (or unreviewed). Pass |
set_budget | write | Set the monthly budget amount for a category. amount= |
set_recurring_state | write | Change the state of a recurring item (subscription/charge). |
split_transaction | read | Split one parent transaction into 2+ child transactions (e.g. a |
spy_tool | read | test double |
update_category | write | Update an existing user-defined category. Provide category_id (required) and any |
update_recurring | write | Update an existing recurring transaction. Pass recurring_id plus at least one of |
update_tag | write | Update an existing tag. Provide tag_id (required) and at least one of name or |
update_transaction | write | Update a single transaction. Pass transaction_id plus at least one of name, |
update_transactions | write | Apply many DIFFERENT transaction edits in ONE call — the per-row bulk form of |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
[/(?<![\w$.])eval\s*\(/, 'eval() call'],
[/(?<![\w$.])new\s+Function\s*\(/, 'new Function() constructor'],
.agents/skills
.claude/skills
Promise.resolve({ token: 'AMf-fake-refresh-token', browser: 'Chrome' })candidates: [{ token: 'AMf-fake-refresh-token', browser: 'Chrome', scoped: true }],candidates: [{ token: 'AMf-foreign-project-token', browser: 'Chrome', scoped: false }],{ token: 'AMf-real-copilot-token', browser: 'Arc', scoped: false },candidates: [{ token: 'AMf-copilot-but-disabled', browser: 'Chrome', scoped: true }],delete_category, delete_recurring, delete_tag, delete_transaction
.mcpbignore
.prettierignore
.prettierrc.json
638-unbounded-trusted-payload-in-budgeted-response.md
AGENTS.md
GEMINI.md
await withTree({ 'node_modules/pkg/index.js': `eval(x);\n` }, ({ code }) =>await withTree({ 'CHANGELOG.md': `${'word '.repeat(200)}eval(x)\n` }, ({ code }) =>{ 'docs/page.mdx': `export const x = 1;${' '.repeat(60)}eval(y);${'z'.repeat(80)}\n` },import { FirebaseAuth } from '../../src/core/auth/firebase-auth.js';import { extractRefreshTokenCandidates } from '../../src/core/auth/browser-token.js';import { CopilotDatabase } from '../../src/core/database.js';import { GraphQLClient } from '../../src/core/graphql/client.js';import { FirebaseAuth } from '../../src/core/auth/firebase-auth.js';@modelcontextprotocol/sdk, classic-level, zod, @anthropic-ai/mcpb, @eslint/js, @types/bun, @types/node, eslint
Gates applied: no_behavioural_pass.
e43f9afe1eb9full audit observations/trust-audit/mcp-server/ignaciohermosillacornejo__copilot-money.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | e43f9afe1eb9 | BLOCK | F | 54 | first audit |
Questions
What is the Copilot Money MCP server?
MCP server for Copilot Money App - AI powered personal finance queries using local data
What tools does Copilot Money expose?
51 in total: 34 read-only, 13 that write, and 4 that can delete or overwrite (delete_category, delete_recurring, delete_tag, delete_transaction). Every one is listed on this page with its risk.
Is Copilot Money safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Copilot Money need?
It reads CHECK_AUTHORSHIP_COMMITS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Copilot Money run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as copilot-money-mcp at 2.3.0.
How current is this page?
The grade is for one exact copy of the source (e43f9afe1eb9), read on 2026-10-07. The repository is watched and re-audited when it changes.