monarch-money-mcp-server
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's finance-access purpose matches its capabilities, but it relies on unofficial third-party code from personal GitHub repos, asks users to submit Monarch credentials/MFA to that code, persists session tokens locally, and enables mutating financial actions. No clear exfiltration or overtly malicious behavior is shown, but the trust and credential-handling model is high risk for such sensitive data.
Confidence: 87%Severity: 72%
Audit Metadata