Atlas / MCP servers / ignaciohermosillacornejo / Copilot Money

Copilot MoneyBLOCK

mcp/ignaciohermosillacornejo/copilot-money

MCP server for Copilot Money App - AI powered personal finance queries using local data

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
51 34r · 13w · 4d
Transport
stdio
License
MIT
Stars
83
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Query and manage your personal finances with AI using local Copilot Money data

[](https://opensource.org/licenses/MIT) [](https://nodejs.org/) [](https://www.typescriptlang.org/) [](https://github.com/ignaciohermosillacornejo/copilot-money-mcp/actions/workflows/test.yml) [](https://codecov.io/gh/ignaciohermosillacornejo/copilot-money-mcp) [](https://glama.ai/mcp/servers/ignaciohermosillacornejo/copilot-money-mcp) [](https://registry.modelcontextprotocol.io/?q=copilot-money-mcp)

Disclaimer

This is an independent, community-driven project and is not affiliated with, endorsed by, or associated with Copilot Money or its parent company in any way. This tool was created by an independent developer to enable AI-powered queries of locally cached data. "Copilot Money" is a trademark of its respective owner.

[!NOTE] Copilot Money has announced an official MCP server (currently in waitlist, read-only). If a first-party, read-only integration suits your needs, you should strongly consider using it instead of this community project. Learn more and join the waitlist at agent.copilot.money. This project remains useful if you need write tools (categorize transactions, manage budgets, edit recurrings, etc.), fully offline cache-mode reads with zero network requests, or simply want
Read from source at commit e43f9afe1eb9OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add copilot-money-mcp -- npx -y [email protected]
03

Exposed tools (51)

34 read · 13 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_transaction_to_recurringwriteManually link an existing transaction to an existing recurring series. Use this when
bulk_edit_transactionswriteApply the SAME edit to MANY transactions in ONE request — Copilot
create_categorywriteCreate a new custom category in Copilot Money. Provide name, color_name,
create_recurringwriteCreate a new recurring/subscription item by seeding it from an existing transaction.
create_tagwriteCreate a new user-defined tag for categorizing transactions. Tags appear in the
create_transactionwriteCreate a brand-new manual transaction on an existing account. Requires
delete_categorydestructiveDelete a user-defined category. The category_id can be obtained from get_categories.
delete_recurringdestructiveDelete a recurring item (subscription/charge).
delete_tagdestructiveDelete a user-defined tag. The tag_id can be obtained from the tag definitions
delete_transactiondestructive**DESTRUCTIVE**: Permanently deletes a transaction from Copilot Money.
get_accountsreadGet all accounts with balances, plus summary fields: total_balance (net worth = assets minus liabilities),
get_accounts_livereadGet all linked financial accounts (live, GraphQL-backed). Returns balances and metadata.
get_aggregated_holdings_livereadGet per-security aggregated holdings (live, GraphQL-backed). One row per security,
get_balance_historyreadGet daily balance snapshots for accounts over time. Each entry returns current_balance,
get_balance_history_livereadGet daily balance history for a single account (live, GraphQL-backed).
get_budgetsreadGet budgets from Copilot
get_budgets_livereadGet budgets from Copilot
get_cache_inforeadGet information about the local data cache, including the date range of cached transactions
get_categoriesreadUnified category retrieval tool. Supports multiple views:
get_categories_livereadGet user categories (live, GraphQL-backed), including each category id, parentId, and a
get_connection_statusreadGet connection status for all linked financial institutions.
get_goal_historyreadGet monthly progress snapshots for financial goals. Returns current_amount,
get_goalsreadGet financial goals from Copilot
get_holdingsreadGet current investment holdings with position-level detail. Returns ticker, name,
get_holdings_livereadGet investment positions with cost-basis metrics (live, GraphQL-backed).
get_investment_allocation_livereadGet the portfolio asset-class allocation (live, GraphQL-backed). Returns one row per
get_investment_balance_livereadGet your investments-only combined balance (live, GraphQL-backed):
get_investment_pricesreadGet investment price history for portfolio tracking. Returns one row per
get_investment_prices_livereadGet price history for a single security (live, GraphQL-backed). time_frame picks the
get_investment_splitsreadGet stock split events from the local Firestore cache. Returns one row
get_monthly_spend_livereadGet the current month
get_networth_livereadGet net-worth-over-time history (live, GraphQL-backed). Returns daily snapshots
get_recurring_livereadGet user-confirmed recurring/subscription items (live, GraphQL-backed).
get_recurring_transactionsreadIdentify recurring/subscription charges. Combines two data sources:
get_tags_livereadGet all user tags (live, GraphQL-backed). Each row carries
get_top_movers_livereadGet the biggest movers across your investment holdings (live, GraphQL-backed).
get_transactionsreadReads from the local LevelDB cache, which may lag behind Copilot
get_transactions_livereadRead and filter transactions live from Copilot
get_upcoming_recurrings_livereadGet the next-due recurring/subscription items — the
refresh_cachereadFlush the in-memory live cache by scope. Use when the user explicitly wants fresh data despite TTLs. Does not touch LevelDB (use refresh_database for that). Live-reads mode only.
refresh_databasereadRefresh the in-memory cache by reloading data from the local Copilot Money database.
review_transactionsreadBulk mark transactions as reviewed (or unreviewed). Pass
set_budgetwriteSet the monthly budget amount for a category. amount=
set_recurring_statewriteChange the state of a recurring item (subscription/charge).
split_transactionreadSplit one parent transaction into 2+ child transactions (e.g. a
spy_toolreadtest double
update_categorywriteUpdate an existing user-defined category. Provide category_id (required) and any
update_recurringwriteUpdate an existing recurring transaction. Pass recurring_id plus at least one of
update_tagwriteUpdate an existing tag. Provide tag_id (required) and at least one of name or
update_transactionwriteUpdate a single transaction. Pass transaction_id plus at least one of name,
update_transactionswriteApply many DIFFERENT transaction edits in ONE call — the per-row bulk form of
04

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (5 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/check-concealment.ts:354
[/(?<![\w$.])eval\s*\(/, 'eval() call'],
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/check-concealment.ts:355
[/(?<![\w$.])new\s+Function\s*\(/, 'new Function() constructor'],
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.agents/skills
.agents/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/superpowers/plans/2026-04-05-firestore-write-operations.md:697
Promise.resolve({ token: 'AMf-fake-refresh-token', browser: 'Chrome' })
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/core/auth/firebase-auth.test.ts:9
candidates: [{ token: 'AMf-fake-refresh-token', browser: 'Chrome', scoped: true }],
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/core/auth/firebase-auth.test.ts:126
candidates: [{ token: 'AMf-foreign-project-token', browser: 'Chrome', scoped: false }],
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/core/auth/firebase-auth.test.ts:149
{ token: 'AMf-real-copilot-token', browser: 'Arc', scoped: false },
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
tests/core/auth/firebase-auth.test.ts:210
candidates: [{ token: 'AMf-copilot-but-disabled', browser: 'Chrome', scoped: true }],
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_category, delete_recurring, delete_tag, delete_transaction
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcpbignore
.mcpbignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.suspicious_name · CWE-1104
docs/bugs/638-unbounded-trusted-payload-in-budgeted-response.md
638-unbounded-trusted-payload-in-budgeted-response.md
Why it matters. member named after an attack tool
Fix. remove or justify
LOWInventory / provenance · inv.symlink · CWE-1104
AGENTS.md
AGENTS.md
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
GEMINI.md
GEMINI.md
Why it matters. link not followed
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/scripts/check-concealment.test.ts:340
await withTree({ 'node_modules/pkg/index.js': `eval(x);\n` }, ({ code }) =>
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/scripts/check-concealment.test.ts:802
await withTree({ 'CHANGELOG.md': `${'word '.repeat(200)}eval(x)\n` }, ({ code }) =>
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/scripts/check-concealment.test.ts:906
{ 'docs/page.mdx': `export const x = 1;${' '.repeat(60)}eval(y);${'z'.repeat(80)}\n` },
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/smoke/_conformance.ts:22
import { FirebaseAuth } from '../../src/core/auth/firebase-auth.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/smoke/_conformance.ts:23
import { extractRefreshTokenCandidates } from '../../src/core/auth/browser-token.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/smoke/_harness.ts:16
import { CopilotDatabase } from '../../src/core/database.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/smoke/_harness.ts:17
import { GraphQLClient } from '../../src/core/graphql/client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
scripts/smoke/_harness.ts:18
import { FirebaseAuth } from '../../src/core/auth/firebase-auth.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, classic-level, zod, @anthropic-ai/mcpb, @eslint/js, @types/bun, @types/node, eslint
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha e43f9afe1eb9full audit observations/trust-audit/mcp-server/ignaciohermosillacornejo__copilot-money.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07e43f9afe1eb9BLOCKF54first audit
06

Questions

What is the Copilot Money MCP server?

MCP server for Copilot Money App - AI powered personal finance queries using local data

What tools does Copilot Money expose?

51 in total: 34 read-only, 13 that write, and 4 that can delete or overwrite (delete_category, delete_recurring, delete_tag, delete_transaction). Every one is listed on this page with its risk.

Is Copilot Money safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Copilot Money need?

It reads CHECK_AUTHORSHIP_COMMITS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Copilot Money run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as copilot-money-mcp at 2.3.0.

How current is this page?

The grade is for one exact copy of the source (e43f9afe1eb9), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement