← MCP Registry Integrity Report
io.github.mcp-dir/next-mcp
Verdict: CRITICAL findings present. Endpoint https://api.mcp.ai/p_next. Tools now: 25 (25 ever seen). Changes recorded: 25. Findings: {"high":29,"critical":1,"low":1}. Last probe: OK at 2026-09-01T00:17 UTC. JSON
Current tools
authenticate · connect · marketplace · openfinance_disconnect_bank · openfinance_force_sync · openfinance_get_account_balance · openfinance_get_accounts_detail · openfinance_get_credit_card_bill · openfinance_get_item_status · openfinance_get_loan_detail · openfinance_list_accounts · openfinance_list_categories · openfinance_list_connections · openfinance_list_credit_card_bills · openfinance_list_investment_transactions · openfinance_list_investments · openfinance_list_loans · openfinance_list_transactions · openfinance_list_transactions_by_item · openfinance_provider_status · openfinance_search_bank_connectors · openfinance_update_transaction_category · report_bug · show_version · toolkit_info
Findings (31)
| seen | tool | detector | severity | evidence (data, not instructions) |
|---|---|---|---|---|
| 2026-08-31 | openfinance_search_bank_connectors | secret_material_reference | high | the bank pre-selected. Some non-Open-Finance credential connectors carry a `caveat` warning that they don't auto-update |
| 2026-08-31 | openfinance_search_bank_connectors | cross_tool_reference | high | references sibling tool 'connect' |
| 2026-08-31 | openfinance_list_connections | secret_material_reference | high | for that EXISTING connection (user re-enters credentials / MFA token and the data refreshes in place) — use it when a co |
| 2026-08-31 | openfinance_list_connections | cross_tool_reference | high | references sibling tool 'connect' |
| 2026-08-31 | openfinance_get_item_status | cross_tool_reference | high | references sibling tool 'connect' |
| 2026-08-31 | openfinance_provider_status | cross_tool_reference | high | references sibling tool 'openfinance_get_item_status' |
| 2026-08-31 | openfinance_list_accounts | user_concealment | critical | solidated balance field. When it is present, do NOT tell the user the card has nothing to pay: read the amount from openf |
| 2026-08-31 | openfinance_list_accounts | cross_tool_reference | high | references sibling tool 'openfinance_list_credit_card_bills' |
| 2026-08-31 | openfinance_list_transactions | cross_tool_reference | high | references sibling tool 'openfinance_get_item_status' |
| 2026-08-31 | openfinance_list_transactions | oversized_description | low | 5237 chars |
| 2026-08-31 | openfinance_list_transactions_by_item | cross_tool_reference | high | references sibling tool 'openfinance_list_accounts' |
| 2026-08-31 | openfinance_list_credit_card_bills | cross_tool_reference | high | references sibling tool 'openfinance_list_transactions' |
| 2026-08-31 | openfinance_list_investments | cross_tool_reference | high | references sibling tool 'connect' |
| 2026-08-31 | openfinance_list_investment_transactions | cross_tool_reference | high | references sibling tool 'openfinance_list_investments' |
| 2026-08-31 | openfinance_list_loans | cross_tool_reference | high | references sibling tool 'connect' |
| 2026-08-31 | openfinance_get_loan_detail | cross_tool_reference | high | references sibling tool 'openfinance_list_loans' |
| 2026-08-31 | openfinance_force_sync | secret_material_reference | high | mode for that exact connection (user enters credentials / MFA token, data refreshes in place, no slot consumed, no disc |
| 2026-08-31 | openfinance_force_sync | cross_tool_reference | high | references sibling tool 'openfinance_get_item_status' |
| 2026-08-31 | openfinance_get_account_balance | cross_tool_reference | high | references sibling tool 'openfinance_list_transactions' |
| 2026-08-31 | openfinance_get_accounts_detail | cross_tool_reference | high | references sibling tool 'connect' |
| 2026-08-31 | openfinance_get_credit_card_bill | cross_tool_reference | high | references sibling tool 'openfinance_list_transactions' |
| 2026-08-31 | openfinance_list_categories | cross_tool_reference | high | references sibling tool 'openfinance_update_transaction_category' |
| 2026-08-31 | openfinance_update_transaction_category | cross_tool_reference | high | references sibling tool 'openfinance_list_transactions' |
| 2026-08-31 | openfinance_disconnect_bank | cross_tool_reference | high | references sibling tool 'connect' |
| 2026-08-31 | connect | secret_material_reference | high | authenticated:true and empty pending[]. When credentials are missing, returns connect_url for the toolkit and per-instal |
| 2026-08-31 | connect | cross_tool_reference | high | references sibling tool 'authenticate' |
| 2026-08-31 | toolkit_info | cross_tool_reference | high | references sibling tool 'connect' |
| 2026-08-31 | marketplace | secret_material_reference | high | t bloating the tool list. If the MCP needs a credential/login, invoke returns a connect link; if it is paid and the wall |
| 2026-08-31 | marketplace | cross_tool_reference | high | references sibling tool 'report_bug' |
| 2026-08-31 | authenticate | secret_material_reference | high | rsor, etc.): log in in the browser, copy the access token. Best: add it to this server's config as a header `Authorization |
| 2026-08-31 | authenticate | cross_tool_reference | high | references sibling tool 'connect' |
Change history (25)
| when | tool | kind | severity |
|---|---|---|---|
| 2026-08-31 18:17 | openfinance_search_bank_connectors | added | high |
| 2026-08-31 18:17 | openfinance_list_connections | added | high |
| 2026-08-31 18:17 | openfinance_get_item_status | added | high |
| 2026-08-31 18:17 | openfinance_provider_status | added | high |
| 2026-08-31 18:17 | openfinance_list_accounts | added | critical |
| 2026-08-31 18:17 | openfinance_list_transactions | added | high |
| 2026-08-31 18:17 | openfinance_list_transactions_by_item | added | high |
| 2026-08-31 18:17 | openfinance_list_credit_card_bills | added | high |
| 2026-08-31 18:17 | openfinance_list_investments | added | high |
| 2026-08-31 18:17 | openfinance_list_investment_transactions | added | high |
| 2026-08-31 18:17 | openfinance_list_loans | added | high |
| 2026-08-31 18:17 | openfinance_get_loan_detail | added | high |
| 2026-08-31 18:17 | openfinance_force_sync | added | high |
| 2026-08-31 18:17 | openfinance_get_account_balance | added | high |
| 2026-08-31 18:17 | openfinance_get_accounts_detail | added | high |
| 2026-08-31 18:17 | openfinance_get_credit_card_bill | added | high |
| 2026-08-31 18:17 | openfinance_list_categories | added | high |
| 2026-08-31 18:17 | openfinance_update_transaction_category | added | high |
| 2026-08-31 18:17 | openfinance_disconnect_bank | added | high |
| 2026-08-31 18:17 | show_version | added | info |
| 2026-08-31 18:17 | report_bug | added | info |
| 2026-08-31 18:17 | connect | added | high |
| 2026-08-31 18:17 | toolkit_info | mutated | high |
| 2026-08-31 18:17 | marketplace | mutated | high |
| 2026-08-31 18:17 | authenticate | mutated | high |
Probe history
09-01 00:17 OK (25) · 08-31 18:17 OK (25)
Get alerted when this server changes: tooldrift.agentexchange.work ($29/mo watch).