← Back to search

@ksefnik/mcp

CodeFormers-it Scanned 5h ago

Model Context Protocol server for Ksefnik — exposes KSeF reconciliation tools to Claude, Cursor and other MCP clients

C
72.8 / 100

Versions

0.5.0latest
May 27, 2026
0.4.0
Apr 13, 2026
0.3.0
Apr 12, 2026
0.2.0
Apr 12, 2026
0.1.0
Apr 12, 2026
+ show 1 moreshow less
0.0.1
Apr 11, 2026
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 9

sync-invoices
annotations: none low

Fetch invoices from KSeF for a given date range

import-bank
annotations: none low

Import bank statement content (auto-detects format)

reconcile
annotations: none low

Run reconciliation pipeline on stored invoices and transactions

get-unmatched
annotations: none low

Get unmatched invoices and transactions from a reconciliation report

query-invoices
annotations: none low

Query stored invoices by NIP, date range, or invoice number

send-invoice
annotations: none low

Send invoice XML to KSeF

validate-invoice
annotations: none low

Validate an invoice against 20 Polish tax rules

confirm-match
annotations: none low

Confirm or reject a reconciliation match

get-upo
annotations: none low

Check UPO (Urzędowe Poświadczenie Odbioru) status for a sent invoice

Permissions 3

network medium
Server uses network capabilities via: fetch()
filesystem low
Server uses filesystem capabilities via: fs sync ops
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 65

low
Tool 'validate-invoice' has no annotations annotation_checker · 100%
low
Tool 'confirm-match' has no annotations annotation_checker · 100%
low
Tool 'sync-invoices' has no annotations annotation_checker · 100%
low
Tool 'import-bank' has no annotations annotation_checker · 100%
low
Tool 'reconcile' has no annotations annotation_checker · 100%
low
Tool 'get-unmatched' has no annotations annotation_checker · 100%
low
Tool 'query-invoices' has no annotations annotation_checker · 100%
low
Tool 'send-invoice' has no annotations annotation_checker · 100%
low
Tool 'get-upo' has no annotations annotation_checker · 100%
medium
OAuth implementation without PKCE auth_checker · 75%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Suspicious package name: react-dom dependency_analyzer · 60%
medium
Vulnerable dependency: vitest@3.2 (GHSA-5xrq-8626-4rwp) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@3.2 (GHSA-82fw-gwwq-j7x9) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-26w7-cxv4-gfx2) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-2pvr-wf23-7pc7) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-376h-93r7-7g6f) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-4g3v-8h47-v7g6) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-5ff5-9fcw-vg88) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-7pw4-f3q4-r2p2) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-8hv8-536x-4wqp) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-cq8c-xv66-36gw) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-f48w-9m4c-m7f5) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-fvmw-cj7j-j39q) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-g735-7g2w-hh3f) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-ggxq-hp9w-j794) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-hr2q-hp5q-x767) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-j687-52p2-xcff) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-jrpj-wcv7-9fh9) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-w2vj-39qv-7vh7) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-whqg-ppgf-wp8c) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-wrwg-2hg8-v723) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-x3h8-62x9-952g) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-xf8x-j4p2-f749) dependency_analyzer · 95%
medium
Vulnerable dependency: astro@5.9 (GHSA-xr5h-phrj-8vxv) dependency_analyzer · 95%
medium
Vulnerable dependency: sharp@0.33 (GHSA-f88m-g3jw-g9cj) dependency_analyzer · 95%
medium
Vulnerable dependency: sharp@0.33 (GHSA-rgj7-g3m4-5g8c) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12 (GHSA-345p-7cg4-v4c7) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12 (GHSA-8r9q-7v3j-jr4g) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.12 (GHSA-w48q-cv73-mx4w) dependency_analyzer · 95%
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-8gc5-j5rx-235r) dependency_analyzer · 95%
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-fj3w-jwp8-x2g3) dependency_analyzer · 95%
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-gh4j-gqv2-49f6) dependency_analyzer · 95%
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-jmr7-xgp7-cmfj) dependency_analyzer · 95%
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-jp2q-39xq-3w4g) dependency_analyzer · 95%
medium
Vulnerable dependency: fast-xml-parser@4.5.0 (GHSA-m7jm-9gc2-mpf2) dependency_analyzer · 95%
medium
Buffer.from base64 in CodeFormers-it-ksefnik-801bfd8/packages/http/src/__tests__/crypto.test.ts:24 entropy_analyzer · 75%
info
package.json metadata manifest_parser · 100%
info
Tool: sync-invoices manifest_parser · 85%
info
Tool: import-bank manifest_parser · 85%
info
Tool: reconcile manifest_parser · 85%
info
Tool: get-unmatched manifest_parser · 85%
info
Tool: query-invoices manifest_parser · 85%
info
Tool: send-invoice manifest_parser · 85%
info
Tool: validate-invoice manifest_parser · 85%
info
Tool: confirm-match manifest_parser · 85%
info
Tool: get-upo manifest_parser · 85%
info
Transport: stdio manifest_parser · 90%
info
Required env vars (13) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
low
Permission: filesystem access detected permission_analyzer · 90%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 36 components sbom_generator · 100%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%