Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.
Warning

Malware flagged

A supply-chain scanner flagged a high-severity malware risk in this package. Treat it as unsafe to install until the finding is cleared. See Supply Chain Security in the trust breakdown.

Copilot Money

NPM · COPILOT-MONEY-MCP · SCANNED AUG 3

Query and manage Copilot Money personal finances — local reads, opt-in GraphQL writes.

Available components

+56 this week 64 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security43
  • Malware check failed: a supply-chain vendor flagged a high-severity malware risk. See how to fix → Fail
  • Only part of the dependency tree could be resolved (108 of 112), so this covers what we could see, not the whole tree.Partial
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (108 of 112), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to ignaciohermosillacornejo/copilot-money-mcp). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 15 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability62
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 2885 tokens (~206/item across 14 items; 14 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · copilot-money-mcp

# add to Claude Code
claude mcp add ignaciohermosillacornejo-copilot-money-mcp -- npx -y copilot-money-mcp
# add to Codex CLI
codex mcp add ignaciohermosillacornejo-copilot-money-mcp -- npx -y copilot-money-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "ignaciohermosillacornejo-copilot-money-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "copilot-money-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add ignaciohermosillacornejo-copilot-money-mcp --command npx --arg -y --arg copilot-money-mcp
# ~/.hermes/config.yaml
mcp_servers:
  ignaciohermosillacornejo-copilot-money-mcp:
    command: "npx"
    args: ["-y", "copilot-money-mcp"]
// mcp.json
{
  "mcpServers": {
    "ignaciohermosillacornejo-copilot-money-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "copilot-money-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 3 Aug 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 2 Aug 26 +45
    • Malware scan: unverified → fail security
    • Known CVEs: unverified → partial security
    • Install scripts: unverified → pass security
    • Provenance: unverified → pass security
    • The attested source repository moved: ignaciohermosillacornejo/copilot-money-mcp security
    • Security disclosure: fail → unverified functional
    • Tool coverage: 100 → unverified functional
    • Schema quality: unverified → good functional
    • Stability: unverified → 0.23 functional
    • MCP protocol: unverified → pass functional
    • Maintenance: unverified → pass functional
    • Dependency health: unverified → partial functional
    • License: unverified → pass functional
    • Licence: MIT functional
  • 1 Aug 26 +13
    • Tool coverage: unverified → 100 functional
  • 31 Jul 26 −20
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −2
    • Malware scan: fail → unverified security
    • Malware indicator gptMalware:Qnf7zr-42MEeHIdSagz9DbhdMCdqD9aVfUjv-bvYchxY cleared security
    • Malware indicator gptMalware:QDdJwghUApMVXSQlBXPOPDPlt8mnpKnJuqcaGbUeqfMA cleared security
  • 28 Jul 26 +19
    • Tool coverage: unverified → 100 functional
    • First check of Schema quality: fail functional
    • First check of Tool coverage: 100 functional
    • First check of Schema quality: unverified functional
    • First check of Schema quality: fail functional
  • 27 Jul 26 8

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 3 Aug 2026 · Analysed npm/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
ignaciohermosillacornejo/copilot-money-mcp
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/ignaciohermosillacornejo/copilot-money-mcp/.github/workflows/npm-publish.yml@refs/heads/main
Rekor log index:
2195389325
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:d5aa532180c368c157c0d67ebf26cafa42e0e03b5a7e2e5ca31c6b8102dca1996cf7fa63e89e736c29aca0e8f074c78c5d155b5da11d61694a0e410e5
Discovery method:
attestation_endpoint
Dependencies 108 packages

108 packages in the resolved dependency tree · 101 deprecated · 37 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 14 exposed · ~2,885 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
get_accounts ~146

Get all accounts with balances, plus summary fields: total_balance (net worth = assets minus liabilities), total_assets, and total_liabilities. Optionally filter by account type (checking, savings, credit, investment). Checks both account_type and subtype fields for better filtering (e.g., finds checking accounts even when account_type is 'depository'). By default, hidden accounts are excluded.

NameTypeReqDescription
account_typestringFilter by account type (checking, savings, credit, loan, investment, depository). Note: summary totals (total_assets, total_liabilities, total_balance) reflect only the filtered subset.
include_hiddenbooleanInclude hidden accounts (default: false)

No output schema declared.

No examples provided.

get_balance_history ~217

Get daily balance snapshots for accounts over time. Each entry returns current_balance, available_balance, limit, account_id, and account_name. The response also includes an `accounts` array listing the distinct account IDs in the paginated page. Requires a granularity parameter (daily, weekly, monthly) to control response size. Weekly and monthly modes downsample by keeping the last data point per period. Filter by account_id and date range.

NameTypeReqDescription
account_idstringFilter by account ID
end_datestringEnd date (YYYY-MM-DD)
granularitystringyesRequired. Controls response density: daily (every day), weekly (one per week), or monthly (one per month). Use weekly or monthly for longer time ranges.
limitintegerMaximum number of results (default: 100, max: 10000)
offsetintegerNumber of results to skip for pagination (default: 0)
start_datestringStart date (YYYY-MM-DD)

No output schema declared.

No examples provided.

get_budgets ~99

Get budgets from Copilot's native budget tracking. Returns the current-month effective budget per category plus the full `amounts` map of per-month overrides for history lookups. For parent categories, the returned `amount` is the resolved total (children + rollovers) that Copilot displays in the Budgets view. Totals use the current-month effective amount.

NameTypeReqDescription
active_onlybooleanOnly return active budgets (default: false)

No output schema declared.

No examples provided.

get_cache_info ~86

Get information about the local data cache, including the date range of cached transactions and total count. Useful for understanding data availability before running historical queries. This tool reads from a local cache that may not contain your complete transaction history. Also reports decode_health: per-collection counts of documents dropped on schema validation failure (a "degraded" status means some cached documents are missing from results).

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_categories ~238

Unified category retrieval tool. Supports multiple views: list (default) - user categories with transaction counts/amounts for a time period; tree - user categories as hierarchical tree; search - search user categories by keyword. Use parent_id to get subcategories. For list view, use period (e.g., "this_month") or start_date/end_date to filter by date. Includes all categories, even those with $0 spent (matching UI behavior).

NameTypeReqDescription
end_datestringEnd date for list view (YYYY-MM-DD format)
parent_idstringGet subcategories of this parent category ID
periodstringTime period for list view (e.g., 'this_month', 'last_month', 'last_30_days', 'this_year'). Takes precedence over start_date/end_date if provided.
querystringSearch query (required for 'search' view)
start_datestringStart date for list view (YYYY-MM-DD format)
viewstringView mode: list (categories with spend totals), tree (parent/child hierarchy), search (find by keyword)

No output schema declared.

No examples provided.

get_connection_status ~123

Get connection status for all linked financial institutions. Shows per-institution sync health including last successful update timestamps for transactions and investments, login requirements, and error states. Use this to check when accounts were last synced or to identify connections needing attention. Also reports decode_health: per-collection counts of cached documents dropped on schema validation failure (a "degraded" status means some documents are missing from results). Also reports scheduled_smoke: the last scheduled API-drift check (pass / fail / auth-missing with timestamp), or null if the weekly job is not installed.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_goal_history ~171

Get monthly progress snapshots for financial goals. Returns current_amount, target_amount, daily data points, and contribution records per month. Filter by goal_id or month range (YYYY-MM). Cache-only: no live-mode (`--live-reads`) counterpart exists because Copilot's GraphQL endpoint does not expose goal data, so this tool always returns cached LevelDB data regardless of the `--live-reads` flag.

NameTypeReqDescription
end_monthstringEnd month (YYYY-MM)
goal_idstringFilter by goal ID
limitintegerMaximum number of results (default: 100, max: 10000)
offsetintegerNumber of results to skip for pagination (default: 0)
start_monthstringStart month (YYYY-MM)

No output schema declared.

No examples provided.

get_goals ~128

Get financial goals from Copilot's native goal tracking. Retrieves user-defined savings goals, debt payoff targets, and investment goals. Returns goal details including target amounts, monthly contributions, status (active/paused), start dates, and tracking configuration. Calculates total target amount across all goals. Cache-only: no live-mode (`--live-reads`) counterpart exists because Copilot's GraphQL endpoint does not expose goal data, so this tool always returns cached LevelDB data regardless of the `--live-reads` flag.

NameTypeReqDescription
active_onlybooleanOnly return active goals (default: false)

No output schema declared.

No examples provided.

get_holdings ~171

Get current investment holdings with position-level detail. Returns ticker, name, quantity, current price, equity value, average cost, and total return per holding. Joins data from account holdings, securities, and optionally historical snapshots. Filter by account or ticker symbol. Note: cost_basis may be unavailable for cash-equivalent positions.

NameTypeReqDescription
account_idstringFilter by investment account ID
include_historybooleanInclude monthly price/quantity snapshots per holding (default: false)
limitintegerMaximum number of results (default: 100, max: 10000)
offsetintegerNumber of results to skip for pagination (default: 0)
ticker_symbolstringFilter by ticker symbol (e.g., "AAPL", "SCHX")

No output schema declared.

No examples provided.

get_investment_prices ~190

Get investment price history for portfolio tracking. Returns daily and high-frequency price data for stocks, ETFs, mutual funds, and crypto. Filter by ticker symbol, date range, or price type (daily/hf). Includes OHLCV data when available.

NameTypeReqDescription
end_datestringEnd date (YYYY-MM-DD or YYYY-MM)
limitintegerMaximum number of results (default: 100, max: 10000)
offsetintegerNumber of results to skip for pagination (default: 0)
price_typestringFilter by price type: daily (monthly aggregates) or hf (high-frequency intraday)
start_datestringStart date (YYYY-MM-DD or YYYY-MM)
ticker_symbolstringFilter by ticker symbol (e.g., "AAPL", "BTC-USD", "VTSAX")

No output schema declared.

No examples provided.

get_investment_splits ~284

Get stock split events from the local Firestore cache. Returns one row per (security, effective_date) with the adjustment multiplier (e.g. 0.1 for a 10-for-1 split — multiply pre-split prices/quantities by this value to convert to the post-split equivalent). Joined with the securities collection so each row includes ticker and name. IMPORTANT: prices returned by `get_investment_prices` and `get_investment_prices_live` are ALREADY split-adjusted by Copilot. Use this tool only when you need the split events themselves (e.g., for narrative or historical-analysis purposes) — you do NOT need to apply these multipliers to the prices yourself. Securities that have never split are not included in the output. Coverage is limited to securities Copilot currently syncs in your local cache (typically currently-held or recently-held).

NameTypeReqDescription
end_datestringOptional. Inclusive upper bound on effective_date (YYYY-MM-DD).
limitintegerMaximum number of rows. Default 100, max 10000.
offsetintegerPagination offset, default 0.
start_datestringOptional. Inclusive lower bound on effective_date (YYYY-MM-DD).
ticker_symbolstringOptional. Case-insensitive ticker filter (e.g. "NVDA").

No output schema declared.

No examples provided.

get_recurring_transactions ~295

Identify recurring/subscription charges. Combines two data sources: (1) Pattern analysis - finds transactions from same merchant with similar amounts, returns estimated frequency, confidence score, and next expected date. (2) Copilot's native subscription tracking - returns user-confirmed subscriptions stored in the app. Both sources are included by default for comprehensive coverage.

NameTypeReqDescription
end_datestringEnd date (YYYY-MM-DD)
include_copilot_subscriptionsbooleanInclude Copilot's native subscription tracking data (default: true). Returns copilot_subscriptions array with user-confirmed subscriptions.
min_occurrencesintegerMinimum number of occurrences to qualify as recurring (default: 2)
namestringFilter by name (case-insensitive partial match). When filtering, returns detailed view with additional fields like min_amount, max_amount, match_string, account info, and transaction history.
periodstringPeriod to analyze (default: last_90_days). Options: this_month, last_month, last_7_days, last_30_days, last_90_days, ytd, this_year, last_year
recurring_idstringFilter by exact recurring ID. When filtering, returns detailed view with additional fields like min_amount, max_amount, match_string, account info, and transaction history.
start_datestringStart date (YYYY-MM-DD)

No output schema declared.

No examples provided.

get_transactions ~666

Reads from the local LevelDB cache, which may lag behind Copilot's server if the macOS app hasn't synced recently. For real-time data use --live-reads with `get_transactions_live`. Unified transaction retrieval tool. Supports multiple modes: (1) Filter-based: Use period, date range, category, merchant, amount filters. (2) Single lookup: Provide transaction_id to get one transaction. (3) Text search: Use query for free-text merchant search. (4) Special types: Use transaction_type for foreign, refunds, credits, duplicates, hsa_eligible, tagged. (5) Location-based: Use city or lat/lon with radius_km. (6) Tag filter: Use tag to find transactions with a specific tag. Returns human-readable category names and normalized merchant names.

NameTypeReqDescription
account_idstringFilter by account ID
categorystringFilter by category (case-insensitive substring)
citystringFilter by city name (partial match)
countrystringFilter by country code (e.g., US, CL)
end_datestringEnd date (YYYY-MM-DD)
exclude_deletedbooleanExclude deleted transactions marked by Plaid (default: true)
exclude_excludedbooleanExclude user-excluded transactions (default: true)
exclude_split_parentsbooleanExclude split-transaction parents (docs with children_transaction_ids). The children already carry the real categorized amounts — returning the parent would double-count the spend. Default: true.
exclude_transfersbooleanExclude transfers between accounts and credit card payments (default: true)
latnumberLatitude for proximity search (use with lon and radius_km)
limitintegerMaximum number of results (default: 100)
lonnumberLongitude for proximity search (use with lat and radius_km)
max_amountnumberMaximum transaction amount
merchantstringFilter by merchant name (case-insensitive substring)
min_amountnumberMinimum transaction amount
offsetintegerNumber of results to skip for pagination (default: 0)
pendingbooleanFilter by pending status (true for pending only, false for settled only)
periodstringPeriod shorthand: this_month, last_month, last_7_days, last_30_days, last_90_days, ytd, this_year, last_year
querystringFree-text search in merchant/transaction names
radius_kmnumberSearch radius in kilometers (default: 10)
regionstringFilter by region/city (case-insensitive substring)
start_datestringStart date (YYYY-MM-DD)
tagstringFilter by tag name (e.g. "vacation")
transaction_idstringGet a single transaction by ID (ignores other filters)
transaction_typestringFilter by special type: foreign (international), refunds, credits (cashback/rewards), duplicates (potential duplicate transactions), hsa_eligible (medical expenses), tagged (has tags)

No output schema declared.

No examples provided.

refresh_database ~71

Refresh the in-memory cache by reloading data from the local Copilot Money database. Use this when the user has recently synced new transactions in the Copilot Money app, or when you suspect the cached data is stale. The cache also auto-refreshes every 5 minutes. Returns the updated cache info after refresh.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.