Look up SWIFT/BIC, IBAN, sanctions, FX, and cross-border payment intelligence.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 27 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The Ohmyfin Banking Intelligence MCP server exposes 34 tools, focused primarily on general-purpose capabilities. Its published description reads: "Look up SWIFT/BIC, IBAN, sanctions, FX, and cross-border payment intelligence". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates Ohmyfin Banking Intelligence F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Hidden instructions in a tool description" and "Hidden instructions in a tool description". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check Ohmyfin Banking Intelligence's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add Ohmyfin Banking Intelligence to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.ohmyfin.ai/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Search banks and financial institutions by name, SWIFT/BIC code, or country. Covers both SWIFT-connected banks and non-SWIFT financial institutions (e-money issuers, payment processors, MFOs, brokerag
Validate an IBAN and identify the institution that holds the account. Performs format check, country-specific length check, and ISO 7064 mod-97 checksum verification. Also returns COUNTRY-level bankin
Get banking rules and requirements for a country. Returns IBAN requirements, SEPA membership, FATF listing status, national currency, account format specifications, and country-specific payment requir
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: fx_timing_advisor
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
wice daily), so do NOT tell the user a payment is "held until the next seRecommendationRemove model-directed instructions from tool descriptions.
tool: transfer_cost
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
n the chain, so do not tell a user that OUR is safe everywhere except the URecommendationRemove model-directed instructions from tool descriptions.
tool: country_export_controls
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
nexus, etc.). IMPORTANT: Each jurisdiction's controls only bind a paymenRecommendationRemove model-directed instructions from tool descriptions.
tool: track_payment
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
eference alone; you MUST first collect three things from the user: 1. amouRecommendationRemove model-directed instructions from tool descriptions.
tool: swift_lookup
A tool description tries to alter the model’s use of another tool.
ull screen, use sanctions_screen for a compliance verdict), and enriched bank prRecommendationDescriptions must describe only their own tool.
tool: country_banking_rules
A tool description tries to alter the model’s use of another tool.
d of training data for any FATF question, and note that the coarse `fatf`RecommendationDescriptions must describe only their own tool.
tool: country_payment_codes
A tool description tries to alter the model’s use of another tool.
es, etc.). Use country_banking_rules first to see which code types a country requireRecommendationDescriptions must describe only their own tool.
tool: fx_rate_history
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ise of how much history exists: our series start at different dates perRecommendationRemove side-channel parameters; constrain tool inputs.
tool: fx_rate_history
A tool description tries to alter the model’s use of another tool.
instead of an empty series. Report that we hold no history rather than desRecommendationDescriptions must describe only their own tool.
tool: fx_volatility
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ty from a short history, not implied volatility, and the sample may beRecommendationRemove side-channel parameters; constrain tool inputs.
tool: fx_timing_advisor
A tool description tries to alter the model’s use of another tool.
rency leg, call country_banking_rules(destination) and read local_clearing.systems.RecommendationDescriptions must describe only their own tool.
tool: bank_holidays
A tool description tries to alter the model’s use of another tool.
m instead of hand-counting. - Next business day and how many consecutive nRecommendationDescriptions must describe only their own tool.
tool: value_date
A tool description tries to alter the model’s use of another tool.
from this tool, bank_holidays or is_business_day_check and resRecommendationDescriptions must describe only their own tool.
tool: settlement_eta
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
s rejected. api_key: Optional API key (internal calls ride the MCPRecommendationRemove side-channel parameters; constrain tool inputs.
tool: settlement_eta
A tool description tries to alter the model’s use of another tool.
rned by bank_holidays / value_date / is_business_day_check, not againRecommendationDescriptions must describe only their own tool.
tool: settlement_eta
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: transfer_cost
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: mcp_register
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
for an Ohmyfin API key to use paid tools. Creates an account and sendRecommendationRemove side-channel parameters; constrain tool inputs.
tool: mcp_register
A tool description tries to alter the model’s use of another tool.
the code, call mcp_verify to complete registration and get your API key.RecommendationDescriptions must describe only their own tool.
tool: mcp_verify
A tool description tries to alter the model’s use of another tool.
After calling mcp_register, check your email for the 6-digit code and passRecommendationDescriptions must describe only their own tool.
tool: sanctions_screen
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
day without an API key. PAID: Unlimited screens with an API key. ChecRecommendationRemove side-channel parameters; constrain tool inputs.
tool: sanctions_screen
A tool description tries to alter the model’s use of another tool.
BIC, or calling swift_lookup, gets a verified answer. Args: name: The pRecommendationDescriptions must describe only their own tool.
tool: sanctions_screen
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: hs_code_lookup
A tool description tries to alter the model’s use of another tool.
d; confirm with goods_classify or a formal classification. Args: hs_code:RecommendationDescriptions must describe only their own tool.
tool: goods_classify
A tool description tries to alter the model’s use of another tool.
the result into export_controls_screen. IMPORTANT, the matcher is lexical, and confidRecommendationDescriptions must describe only their own tool.
tool: track_payment
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
). Requires an API key with an active FI subscription. To get started:RecommendationRemove side-channel parameters; constrain tool inputs.
tool: track_payment
A tool description tries to alter the model’s use of another tool.
r instead of improvising; a miss on a reference-only trace isRecommendationDescriptions must describe only their own tool.
tool: track_payment
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: tracking_history
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ing", check the history: the earlier result you're being asked abouRecommendationRemove side-channel parameters; constrain tool inputs.
tool: tracking_history
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: ssi_lookup
A tool description tries to alter the model’s use of another tool.
nt numbers. Use swift_lookup() to find the bank's own published correspondRecommendationDescriptions must describe only their own tool.
tool: ssi_lookup
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: banks_using_correspondent
A tool description tries to alter the model’s use of another tool.
ncy. Inverse of ssi_lookup. Returns only swift + name per bank — to retriRecommendationDescriptions must describe only their own tool.
tool: banks_using_correspondent
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: company_search_person
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ult: true). api_key: Your Ohmyfin API key (prod-...). Can also be pRecommendationRemove side-channel parameters; constrain tool inputs.
tool: company_search_person
A tool description tries to alter the model’s use of another tool.
G, UK, XX. Call company_registries() for the live list — this one can go stale. XRecommendationDescriptions must describe only their own tool.
tool: company_search_person
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: company_search_company
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
lt: false). api_key: Your Ohmyfin API key (prod-...). Can also be pRecommendationRemove side-channel parameters; constrain tool inputs.
tool: company_search_company
A tool description tries to alter the model’s use of another tool.
G, UK, XX. Call company_registries() for the live list — this one can go stale. XRecommendationDescriptions must describe only their own tool.
tool: company_search_company
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: company_search_result
A tool description tries to alter the model’s use of another tool.
arch ID. Every company_search_person and company_search_company call returns a searcRecommendationDescriptions must describe only their own tool.
tool: company_search_result
The input schema declares a parameter that asks the caller to hand over a password, key, token, or other secret — a credential-harvest / token-passthrough risk. (Bare pagination `token` params are excluded.)
parameter "api_key"RecommendationNever pass secrets as tool arguments; authenticate out-of-band and remove credential parameters from the schema.
tool: company_registries
A tool description tries to alter the model’s use of another tool.
you can use in company_search_person and company_search_company. This is the LIVE liRecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
n API key, call mcp_register then mcp_verify. FI-tier tools require an FI suRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: payment_cutoff_times
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "payment_cutoff_times"RecommendationScope tools to the minimum needed.
tool: fx_timing_advisor
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "fx_timing_advisor"RecommendationScope tools to the minimum needed.
tool: bank_holidays
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "bank_holidays"RecommendationScope tools to the minimum needed.
tool: value_date
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "value_date"RecommendationScope tools to the minimum needed.
tool: settlement_eta
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "settlement_eta"RecommendationScope tools to the minimum needed.
tool: transfer_cost
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "transfer_cost"RecommendationScope tools to the minimum needed.
tool: mcp_register
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "mcp_register"RecommendationScope tools to the minimum needed.
tool: federal_register_changes
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "federal_register_changes"RecommendationScope tools to the minimum needed.
tool: track_payment
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "track_payment"RecommendationScope tools to the minimum needed.
tool: tracking_history
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "tracking_history"RecommendationScope tools to the minimum needed.
tool: banks_using_correspondent
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "banks_using_correspondent"RecommendationScope tools to the minimum needed.
tool: fx_rate_history
An unusually long description is a common injection-padding tactic.
description length 2016 charsRecommendationKeep descriptions concise.
tool: gpi_status_codes
An unusually long description is a common injection-padding tactic.
description length 2064 charsRecommendationKeep descriptions concise.
tool: fx_volatility
An unusually long description is a common injection-padding tactic.
description length 2531 charsRecommendationKeep descriptions concise.
tool: settlement_eta
An unusually long description is a common injection-padding tactic.
description length 3953 charsRecommendationKeep descriptions concise.
tool: transfer_cost
An unusually long description is a common injection-padding tactic.
description length 3774 charsRecommendationKeep descriptions concise.
tool: sanctions_screen
An unusually long description is a common injection-padding tactic.
description length 2319 charsRecommendationKeep descriptions concise.
tool: export_controls_screen
An unusually long description is a common injection-padding tactic.
description length 2363 charsRecommendationKeep descriptions concise.
tool: track_payment
An unusually long description is a common injection-padding tactic.
description length 5822 charsRecommendationKeep descriptions concise.
tool: ssi_lookup
An unusually long description is a common injection-padding tactic.
description length 3361 charsRecommendationKeep descriptions concise.
tool: company_search_company
An unusually long description is a common injection-padding tactic.
description length 2062 charsRecommendationKeep descriptions concise.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Look up country-specific payment codes (KNP, purpose codes, etc.). Use country_banking_rules first to see which code types a country requires (in the payment_requirements block), then use this tool to
Get the latest available reference (mid-market) exchange rate for a pair. Rates are the official ECB euro foreign-exchange reference rates where the ECB publishes the currency; pairs whose currency th
Get the historical reference exchange-rate series for a currency pair. Returns `series` (the daily rates) plus the metadata needed to describe it honestly. READ `series_coverage` BEFORE CHARACTERISING
Explain SWIFT GPI tracking status codes and provide stuck-payment investigation guidance. USE THIS TOOL FIRST whenever the user reports a payment that is stuck, delayed, not arriving, held, pending, r
Look up SWIFT message types — MT (FIN) and MX (ISO 20022). Pass a specific type to get full details, or omit to list all types. Covers customer payments (MT103, pacs.008), FI transfers (MT202, pacs.00
Get payment system cutoff times for major clearing systems. Covers RTGS (T2 — formerly TARGET2, CHAPS, Fedwire, BOJ-NET, SIC), net settlement (CHIPS, BACS), SEPA schemes (SCT, SCT Inst, OCT Inst, SDD
Get realized FX volatility for a currency pair, and size the FX risk on an exposure held to a future date. Computes 30-day and 90-day annualized volatility from historical ECB reference rates (standar
Get FX trading windows for FX execution timing and spread / rate optimization. Returns market sessions and liquidity windows for a currency. Use this to understand: - **Rate optimization** (primary, r
Compare payment methods and investigate fee deductions for a country pair. Evaluates SEPA vs SWIFT vs domestic options. Also explains SWIFT charge options (OUR/SHA/BEN) and fee investigation — use thi
Get bank/public holidays for a country with payment impact analysis. Returns all public holidays plus a 'payment_impact' section that shows: - Whether today is a business day or holiday in this countr
Check if a specific date is a business day in a country. Accounts for weekends (country-specific) and public holidays. Returns whether the date is a business day, and if not, why (weekend or specific
Calculate the value/settlement date for a payment. Determines when a payment will settle based on: - Source and destination country holiday calendars - Weekend conventions (Sat/Sun or Fri/Sat) - Curre
BETA. Estimate when a SWIFT payment will arrive: a corpus-grounded arrival window with an honest tail, computed from real completed payments we have tracked, projected onto the currency's banking cale
BETA. Estimate what a cross-border payment will COST: the sending bank's published fee, what correspondents typically deduct in transit, and what the beneficiary is likely to receive. This estimator i
Register for an Ohmyfin API key to use paid tools. Creates an account and sends a 6-digit verification code to your email. After receiving the code, call mcp_verify to complete registration and get yo
Verify your email and receive your API key. After calling mcp_register, check your email for the 6-digit code and pass it here. On success, returns your production and test API keys. You must subscrib
Screen a name against global sanctions and watchlists. FREE TIER: 3 screens per day without an API key. PAID: Unlimited screens with an API key. Checks the name against 300+ sanctions, designation and
Look up an Export Control Classification Number (ECCN). Pure reference tool — returns classification details, controlled jurisdictions, and license requirements for the given ECCN. ECCNs are alphanume
Look up export control restrictions for a specific country. Returns embargo status, sanctioned programs, control reasons, and restriction details across jurisdictions (US EAR, EU, UN, etc.) for the gi
Screen goods for export-control restrictions to a destination country. Combines the goods classification with the destination's restriction status and returns whether a license is required, the risk l
Reverse-lookup an HS code → mapped export-control classifications (ECCNs). For customs brokers / shippers who have an HS (Harmonized System) code and need to know which export-control classifications
Classify goods for export control from a description (or HS code). Bilingual (English / Russian, auto-detected) goods classifier. Returns the best-matching HS code (with EN+RU descriptions), related E
Get recent US regulatory changes from BIS and OFAC. Returns Federal Register publications including entity list updates, rule changes, country policy shifts, and new sanctions programs. Args: agency:
Track a SWIFT payment by UETR or reference number. Basic SWIFT payment tracking enriched by data from certain banks in the correspondent chain. Returns the overall payment status and, when available,
Show how a SWIFT payment's tracking results changed over time. Returns the DISTINCT tracking results recorded for a payment (by UETR or reference), deduplicated so ten identical re-tracks collapse to
Look up correspondent banking / settlement instructions (SSI) for a bank. Returns the correspondent banks (nostro accounts) that a given bank uses to settle payments in a specific currency, including
Reverse SSI lookup — find banks that use a given correspondent for a currency. Given a correspondent BIC, currency, and origin country, returns the banks in that country that have a declared nostro at
EXPERIMENTAL — Search company registries for a person's directorships, officer roles, and shareholdings. Searches worldwide company registries to find where a person holds director, officer, or shareh
EXPERIMENTAL — Search company registries for a company with its officers and shareholders. Find company registrations across worldwide registries, including directors, officers, and beneficial owners
EXPERIMENTAL — Retrieve cached company search results by search ID. Every company_search_person and company_search_company call returns a search_id. Use this tool to retrieve those results again witho
EXPERIMENTAL — List available company registries and supported jurisdictions. Returns the list of company registries that can be searched, along with the jurisdiction codes you can use in company_sear