← Back to search Server uses network capabilities via: fetch() Server uses filesystem capabilities via: fs sync ops Server uses env_vars capabilities via: process.env
@ksefnik/mcp
Model Context Protocol server for Ksefnik — exposes KSeF reconciliation tools to Claude, Cursor and other MCP clients
C
72.8 / 100
Versions
0.5.0latestMay 27, 2026
0.4.0Apr 13, 2026
0.3.0Apr 12, 2026
0.2.0Apr 12, 2026
0.1.0Apr 12, 2026
+ show 1 moreshow less
0.0.1Apr 11, 2026
Tools 9
sync-invoices annotations: none low
Fetch invoices from KSeF for a given date range
import-bank annotations: none low
Import bank statement content (auto-detects format)
reconcile annotations: none low
Run reconciliation pipeline on stored invoices and transactions
get-unmatched annotations: none low
Get unmatched invoices and transactions from a reconciliation report
query-invoices annotations: none low
Query stored invoices by NIP, date range, or invoice number
send-invoice annotations: none low
Send invoice XML to KSeF
validate-invoice annotations: none low
Validate an invoice against 20 Polish tax rules
confirm-match annotations: none low
Confirm or reject a reconciliation match
get-upo annotations: none low
Check UPO (Urzędowe Poświadczenie Odbioru) status for a sent invoice
Permissions 3
network medium filesystem low env_vars low Scan Findings 65
low
Tool 'validate-invoice' has no annotations
low
Tool 'confirm-match' has no annotations
low
Tool 'sync-invoices' has no annotations
low
Tool 'import-bank' has no annotations
low
Tool 'reconcile' has no annotations
low
Tool 'get-unmatched' has no annotations
low
Tool 'query-invoices' has no annotations
low
Tool 'send-invoice' has no annotations
low
Tool 'get-upo' has no annotations
medium
OAuth implementation without PKCE
info
Sandbox failed to start for behavioral verification
medium
Suspicious package name: react-dom
medium
Vulnerable dependency: vitest@3.2 (GHSA-5xrq-8626-4rwp)
medium
Vulnerable dependency: vitest@3.2 (GHSA-82fw-gwwq-j7x9)
medium
Vulnerable dependency: astro@5.9 (GHSA-26w7-cxv4-gfx2)
medium
Vulnerable dependency: astro@5.9 (GHSA-2pvr-wf23-7pc7)
medium
Vulnerable dependency: astro@5.9 (GHSA-376h-93r7-7g6f)
medium
Vulnerable dependency: astro@5.9 (GHSA-4g3v-8h47-v7g6)
medium
Vulnerable dependency: astro@5.9 (GHSA-5ff5-9fcw-vg88)
medium
Vulnerable dependency: astro@5.9 (GHSA-7pw4-f3q4-r2p2)
medium
Vulnerable dependency: astro@5.9 (GHSA-8hv8-536x-4wqp)
medium
Vulnerable dependency: astro@5.9 (GHSA-cq8c-xv66-36gw)
medium
Vulnerable dependency: astro@5.9 (GHSA-f48w-9m4c-m7f5)
medium
Vulnerable dependency: astro@5.9 (GHSA-fvmw-cj7j-j39q)
medium
Vulnerable dependency: astro@5.9 (GHSA-g735-7g2w-hh3f)
medium
Vulnerable dependency: astro@5.9 (GHSA-ggxq-hp9w-j794)
medium
Vulnerable dependency: astro@5.9 (GHSA-hr2q-hp5q-x767)
medium
Vulnerable dependency: astro@5.9 (GHSA-j687-52p2-xcff)
medium
Vulnerable dependency: astro@5.9 (GHSA-jrpj-wcv7-9fh9)
medium
Vulnerable dependency: astro@5.9 (GHSA-w2vj-39qv-7vh7)
medium
Vulnerable dependency: astro@5.9 (GHSA-whqg-ppgf-wp8c)
medium
Vulnerable dependency: astro@5.9 (GHSA-wrwg-2hg8-v723)
medium
Vulnerable dependency: astro@5.9 (GHSA-x3h8-62x9-952g)
medium
Vulnerable dependency: astro@5.9 (GHSA-xf8x-j4p2-f749)
medium
Vulnerable dependency: astro@5.9 (GHSA-xr5h-phrj-8vxv)
medium
Vulnerable dependency: sharp@0.33 (GHSA-f88m-g3jw-g9cj)
medium
Vulnerable dependency: sharp@0.33 (GHSA-rgj7-g3m4-5g8c)
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12 (GHSA-345p-7cg4-v4c7)
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12 (GHSA-8r9q-7v3j-jr4g)
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12 (GHSA-w48q-cv73-mx4w)
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-8gc5-j5rx-235r)
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-fj3w-jwp8-x2g3)
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-gh4j-gqv2-49f6)
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-jmr7-xgp7-cmfj)
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-jp2q-39xq-3w4g)
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-m7jm-9gc2-mpf2)
medium
Buffer.from base64 in CodeFormers-it-ksefnik-801bfd8/packages/http/src/__tests__/crypto.test.ts:24
info
package.json metadata
info
Tool: sync-invoices
info
Tool: import-bank
info
Tool: reconcile
info
Tool: get-unmatched
info
Tool: query-invoices
info
Tool: send-invoice
info
Tool: validate-invoice
info
Tool: confirm-match
info
Tool: get-upo
info
Transport: stdio
info
Required env vars (13)
info
Sandbox failed to start for output poisoning scan
medium
Permission: network access detected
low
Permission: filesystem access detected
low
Permission: env_vars access detected
info
SBOM generated: 36 components
medium
No build provenance detected (SLSA L0)