{
 "server": "io.github.mcp-dir/nubank-mcp",
 "url": "https://api.mcp.ai/p_nubank",
 "verdict": "CRITICAL findings present",
 "current_tool_count": 25,
 "tools_ever_seen": 25,
 "drift_events": 25,
 "findings_by_severity": {
  "high": 29,
  "critical": 1,
  "low": 1
 },
 "last_probe": {
  "status": "OK",
  "n_tools": 25,
  "ran_at": "2026-09-01T00:17:50.751Z"
 },
 "current_tools": [
  "authenticate",
  "connect",
  "marketplace",
  "openfinance_disconnect_bank",
  "openfinance_force_sync",
  "openfinance_get_account_balance",
  "openfinance_get_accounts_detail",
  "openfinance_get_credit_card_bill",
  "openfinance_get_item_status",
  "openfinance_get_loan_detail",
  "openfinance_list_accounts",
  "openfinance_list_categories",
  "openfinance_list_connections",
  "openfinance_list_credit_card_bills",
  "openfinance_list_investment_transactions",
  "openfinance_list_investments",
  "openfinance_list_loans",
  "openfinance_list_transactions",
  "openfinance_list_transactions_by_item",
  "openfinance_provider_status",
  "openfinance_search_bank_connectors",
  "openfinance_update_transaction_category",
  "report_bug",
  "show_version",
  "toolkit_info"
 ],
 "drift": [
  {
   "tool": "openfinance_search_bank_connectors",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_connections",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_item_status",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_provider_status",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_accounts",
   "kind": "mutated",
   "severity": "critical",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_transactions",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_transactions_by_item",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_credit_card_bills",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_investments",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_investment_transactions",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_loans",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_loan_detail",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_force_sync",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_account_balance",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_accounts_detail",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_credit_card_bill",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_categories",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_update_transaction_category",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_disconnect_bank",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "show_version",
   "kind": "mutated",
   "severity": "medium",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "report_bug",
   "kind": "mutated",
   "severity": "medium",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "connect",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "toolkit_info",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "marketplace",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "authenticate",
   "kind": "mutated",
   "severity": "high",
   "detected_at": "2026-09-01T00:17:50.751Z"
  }
 ],
 "findings": [
  {
   "tool": "openfinance_search_bank_connectors",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "the bank pre-selected. Some non-Open-Finance credential connectors carry a `caveat` warning that they don't auto-update",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_search_bank_connectors",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'connect'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_connections",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "for that EXISTING connection (user re-enters credentials / MFA token and the data refreshes in place) — use it when a co",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_connections",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'connect'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_item_status",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'connect'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_provider_status",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_get_item_status'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_accounts",
   "detector": "user_concealment",
   "severity": "critical",
   "field": "description",
   "evidence": "solidated balance field. When it is present, do NOT tell the user the card has nothing to pay: read the amount from openf",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_accounts",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_list_credit_card_bills'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_transactions",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_get_item_status'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_transactions",
   "detector": "oversized_description",
   "severity": "low",
   "field": "description",
   "evidence": "5237 chars",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_transactions_by_item",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_list_accounts'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_credit_card_bills",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_list_transactions'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_investments",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'connect'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_investment_transactions",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_list_investments'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_loans",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'connect'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_loan_detail",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_list_loans'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_force_sync",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "mode for that exact connection (user enters credentials / MFA token, data refreshes in place, no slot consumed, no disc",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_force_sync",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_get_item_status'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_account_balance",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_list_transactions'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_accounts_detail",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'connect'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_get_credit_card_bill",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_list_transactions'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_list_categories",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_update_transaction_category'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_update_transaction_category",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'openfinance_list_transactions'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "openfinance_disconnect_bank",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'connect'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "connect",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "authenticated:true and empty pending[]. When credentials are missing, returns connect_url for the toolkit and per-instal",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "connect",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'authenticate'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "toolkit_info",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'connect'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "marketplace",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "t bloating the tool list. If the MCP needs a credential/login, invoke returns a connect link; if it is paid and the wall",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "marketplace",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'report_bug'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "authenticate",
   "detector": "secret_material_reference",
   "severity": "high",
   "field": "description",
   "evidence": "rsor, etc.): log in in the browser, copy the access token. Best: add it to this server's config as a header `Authorization",
   "seen_at": "2026-09-01T00:17:50.751Z"
  },
  {
   "tool": "authenticate",
   "detector": "cross_tool_reference",
   "severity": "high",
   "field": "description",
   "evidence": "references sibling tool 'connect'",
   "seen_at": "2026-09-01T00:17:50.751Z"
  }
 ],
 "probes": [
  {
   "status": "OK",
   "n_tools": 25,
   "ran_at": "2026-09-01T00:17:50.751Z"
  }
 ]
}