Automates IFRS/IAS financial reporting with 200+ transaction types and audit-trail journal entries.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 6 days ago
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The ifrCoworker MCP server exposes 21 tools, focused primarily on database and AI capabilities. Its published description reads: "Automates IFRS/IAS financial reporting with 200+ transaction types and audit-trail journal entries". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates ifrCoworker F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Hidden instructions in a tool description" and "Hidden instructions in a tool description". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check ifrCoworker's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add ifrCoworker to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://mcp.ifrcoworker.comStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
If you know the economic object type but not the standard, pass `elementType` (e.g. 'lease', 'asset', 'financial-instrument') instead of `standard`. For multi-standard types (asset, equity-method-inve
If you know the economic object type but not the standard, pass `elementType` instead of `standard`. The discriminator field (`assetClass` for 'asset', `investmentType` for 'equity-method-investment')
If you know the economic object type but not the standard, pass `elementType` instead of `standard`. The discriminator field (`assetClass` for 'asset', `investmentType` for 'equity-method-investment')
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: ifr_route_event
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
nt-label items. BEFORE calling ifr_calculate with standard "direct-item": read the MCP resource ifrs://reference/direct…RecommendationRemove model-directed instructions from tool descriptions.
tool: (server instructions)
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
rce read first) Before calling ifr_period_end_batch, you MUST read the ifrs://reference/accounting-policy-choicesRecommendationRemove model-directed instructions from tool descriptions.
tool: ifr_schema
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
lculation task. TOKEN ERROR: if this tool returns success:false withRecommendationRemove side-channel parameters; constrain tool inputs.
tool: ifr_schema
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
com/access` via bash; Claude web: display "Your ifrCoworker access nRecommendationAnnotate destructive tools and require human approval.
tool: ifr_schema
A tool description tries to alter the model’s use of another tool.
nt') instead of `standard`. For multi-standard types (asset, equity-methodRecommendationDescriptions must describe only their own tool.
tool: ifr_schema
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
mmediately run `open https://ifrcoworker.com/access` via bash; Claude web:RecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: ifr_validate
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
lculation task. TOKEN ERROR: if this tool returns success:false withRecommendationRemove side-channel parameters; constrain tool inputs.
tool: ifr_validate
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
com/access` via bash; Claude web: display "Your ifrCoworker access nRecommendationAnnotate destructive tools and require human approval.
tool: ifr_validate
A tool description tries to alter the model’s use of another tool.
e` instead of `standard`. The discriminator field (`assetClass` for 'assetRecommendationDescriptions must describe only their own tool.
tool: ifr_validate
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
mmediately run `open https://ifrcoworker.com/access` via bash; Claude web:RecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: ifr_calculate
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
lculation task. TOKEN ERROR: if this tool returns success:false withRecommendationRemove side-channel parameters; constrain tool inputs.
tool: ifr_calculate
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
com/access` via bash; Claude web: display "Your ifrCoworker access nRecommendationAnnotate destructive tools and require human approval.
tool: ifr_calculate
A tool description tries to alter the model’s use of another tool.
` instead of `standard`. The discriminator field (`assetClass` for 'asset'RecommendationDescriptions must describe only their own tool.
tool: ifr_calculate
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
ntains a direct download link for an 8-sheet Excel workbook (Journal Entries,RecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: ifr_apply_ias10
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
lculation task. TOKEN ERROR: if this tool returns success:false withRecommendationRemove side-channel parameters; constrain tool inputs.
tool: ifr_apply_ias10
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
com/access` via bash; Claude web: display "Your ifrCoworker access nRecommendationAnnotate destructive tools and require human approval.
tool: ifr_apply_ias10
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
mmediately run `open https://ifrcoworker.com/access` via bash; Claude web:RecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: ifr_route_event
A tool description tries to alter the model’s use of another tool.
instead of deriving routing yourself. The matched standards (top 3, with rRecommendationDescriptions must describe only their own tool.
tool: ifr_input_schema
A tool description tries to alter the model’s use of another tool.
without calling ifr_schema. Returns a standard JSON Schema object suitableRecommendationDescriptions must describe only their own tool.
tool: ifr_period_checklist
A tool description tries to alter the model’s use of another tool.
together as an ifr_period_end_batch (which sorts internally). For each standard, caRecommendationDescriptions must describe only their own tool.
tool: ifr_period_end_batch
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
urned journalCsvFile content and the financialStatements into the Google SheRecommendationRemove side-channel parameters; constrain tool inputs.
tool: ifr_period_end_batch
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
com/access` via bash; Claude web: display "Your ifrCoworker access nRecommendationAnnotate destructive tools and require human approval.
tool: ifr_period_end_batch
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: ifr_period_end_batch
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
mmediately run `open https://ifrcoworker.com/access` via bash; Claude web:RecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: ifr_batch_validate
A tool description tries to alter the model’s use of another tool.
t validator for ifr_period_end_batch. Validates every item in one call and returns aRecommendationDescriptions must describe only their own tool.
tool: ifr_ingest_document
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
com/access` via bash; Claude web: display "Your ifrCoworker access nRecommendationAnnotate destructive tools and require human approval.
tool: ifr_ingest_document
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: ifr_propose_mapping
A tool description tries to alter the model’s use of another tool.
before calling ifr_calculate. Never auto-calculate from unverified OCR data.RecommendationDescriptions must describe only their own tool.
tool: ifr_flag_result
A tool description tries to alter the model’s use of another tool.
ar hex from the ifr_schema response you used when building the input. ThisRecommendationDescriptions must describe only their own tool.
tool: ifr_explain_result
A tool description tries to alter the model’s use of another tool.
tionId from any ifr_calculate or ifr_period_end_batch response (valid for 10RecommendationDescriptions must describe only their own tool.
tool: ifr_disclosure_checklist
A tool description tries to alter the model’s use of another tool.
ulations` (full ifr_calculate responses or a whole ifr_period_end_batch resulRecommendationDescriptions must describe only their own tool.
tool: ifr_replay
A tool description tries to alter the model’s use of another tool.
l output. Every ifr_calculate response carries an `audit` envelope { inputEchRecommendationDescriptions must describe only their own tool.
tool: ifr_ecl_provision_matrix
A tool description tries to alter the model’s use of another tool.
s, bonds) — use ifr_calculate with standard "ifrs9" for those. Token requiredRecommendationDescriptions must describe only their own tool.
tool: ifr_check_quota
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
com/access` via bash; Claude web: display "Your ifrCoworker access nRecommendationAnnotate destructive tools and require human approval.
tool: ifr_amortisation_schedule
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
lculation task. TOKEN ERROR: if this tool returns success:false withRecommendationRemove side-channel parameters; constrain tool inputs.
tool: ifr_amortisation_schedule
Tools that execute commands / write files / make arbitrary requests are exposed without annotations or guards.
com/access` via bash; Claude web: display "Your ifrCoworker access nRecommendationAnnotate destructive tools and require human approval.
tool: ifr_amortisation_schedule
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
mmediately run `open https://ifrcoworker.com/access` via bash; Claude web:RecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: ifr_generate_workpaper
A tool description tries to alter the model’s use of another tool.
e or more prior ifr_calculate results. Aggregates across standards: accountinRecommendationDescriptions must describe only their own tool.
tool: ifr_calculation_sheets
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
Id} with Bearer token) and a structured JSON summary of each sheet'sRecommendationRemove side-channel parameters; constrain tool inputs.
tool: ifr_calculation_sheets
A tool description tries to alter the model’s use of another tool.
ook for a prior ifr_calculate or ifr_period_end_batch call. Returns a downloaRecommendationDescriptions must describe only their own tool.
tool: (server instructions)
A tool description tries to alter the model’s use of another tool.
d of you inventing a number. **Explicit disambiguation phrases (say theseRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: ifr_schema
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "ifr_schema"RecommendationScope tools to the minimum needed.
tool: ifr_schema
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ately run `open https://ifrcoworker.com/access` via bash; Claude web: display "Your ifrCoworkerRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ifr_validate
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "ifr_validate"RecommendationScope tools to the minimum needed.
tool: ifr_validate
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ately run `open https://ifrcoworker.com/access` via bash; Claude web: display "Your ifrCoworkerRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ifr_calculate
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "ifr_calculate"RecommendationScope tools to the minimum needed.
tool: ifr_calculate
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ately run `open https://ifrcoworker.com/access` via bash; Claude web: display "Your ifrCoworkerRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ifr_apply_ias10
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "ifr_apply_ias10"RecommendationScope tools to the minimum needed.
tool: ifr_apply_ias10
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ately run `open https://ifrcoworker.com/access` via bash; Claude web: display "Your ifrCoworkerRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ifr_route_event
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "ifr_route_event"RecommendationScope tools to the minimum needed.
tool: ifr_period_end_batch
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "ifr_period_end_batch"RecommendationScope tools to the minimum needed.
tool: ifr_period_end_batch
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ately run `open https://ifrcoworker.com/access` via bash; Claude web: display "Your ifrCoworkerRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ifr_ingest_document
The server advertises open-world / broadly-scoped capabilities.
no annotations on write-capable tool "ifr_ingest_document"RecommendationScope tools to the minimum needed.
tool: ifr_ingest_document
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ately run `open https://ifrcoworker.com/access` via bash; Claude web: display "Your ifrCoworkerRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ifr_check_quota
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ately run `open https://ifrcoworker.com/access` via bash; Claude web: display "Your ifrCoworkerRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ifr_amortisation_schedule
The description pairs a fetch imperative with a hardcoded external URL, letting the server relocate its real instructions off-metadata and mutate them after review. Fires only when a fetch verb and a URL co-occur, so benign documentation links do not.
ately run `open https://ifrcoworker.com/access` via bash; Claude web: display "Your ifrCoworkerRecommendationDo not direct the model to fetch and act on external URLs; treat linked content as untrusted.
tool: ifr_schema
An unusually long description is a common injection-padding tactic.
description length 2484 charsRecommendationKeep descriptions concise.
tool: ifr_calculate
An unusually long description is a common injection-padding tactic.
description length 5994 charsRecommendationKeep descriptions concise.
tool: ifr_period_end_batch
An unusually long description is a common injection-padding tactic.
description length 7737 charsRecommendationKeep descriptions concise.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Apply IAS 10 (Events After Reporting Period) overlay to a prior calculation output. Classifies events as adjusting/non-adjusting, assesses going concern, generates adjusted journal entries. Most stand
ROUTER — the entry point for every business event. Describe what happened in plain language ("bought a machine", "signed an office lease", "customer went bankrupt") and get back the exact call to make
Returns the JSON Schema for the input to ifr_calculate for a given standard. Use this to discover required fields, enum values, and defaults without calling ifr_schema. Returns a standard JSON Schema
Planning tool for a full period-end close. Pass an entityProfile of fact flags (hasInventory, hasPPE, hasLeases, hasFinancialInstruments, isGroup, isListed, incomeTaxApplicable, etc.) and get back the
THE period-end execution tool — process multiple IFRS calculations for a reporting period in one call (year-end, quarter-end, or month-end). One tool, three modes: (1) PLAIN BATCH (default): items + a
FREE pre-flight validator for ifr_period_end_batch. Validates every item in one call and returns all missing required fields across the batch. STRICT GATE: do not call ifr_period_end_batch if allValid
Extract structured data from a PDF (contract, invoice, lease, bond indenture) using Google Document AI. Requires docuScanAccess on the token — returns 403 otherwise; do NOT retry or offer document sca
Map OCR data from ifr_ingest_document into an IFRS standard's input schema and validate it. Returns proposedInput, unmappedFields, missingRequiredFields, validation errors/warnings, needsUserInput[],
Flag a calculation result you believe is incorrect for expert review. Call immediately when the server output appears to contradict IFRS — wrong amount, missing journal entry, incorrect OCI/P&L routin
Return a human-readable explanation of a previously computed calculation. Pass the correlationId from any ifr_calculate or ifr_period_end_batch response (valid for 10 min), OR pass the full prior resp
Generate a disclosure-needs checklist for the period-end. FREE — no credit charged. Input: entityProfile fact flags (same shape as ifr_period_checklist) → returns the core MANDATORY disclosure require
Deterministic audit replay — recompute a prior calculation from its input and verify it reproduces the stored output. FREE — no credit charged. The engine is stateless and pure: identical input + iden
IFRS 9 Simplified Approach — ECL provision matrix for trade receivables, IFRS 15 contract assets, and IFRS 16 lease receivables. Ages each receivable into buckets (current / 1-30 / 31-60 / 61-90 / 91-
IAS 36 — Cash-Generating Unit (CGU) multi-asset impairment test. Applies the 3-step allocation (IAS 36.104-105): Step 1 assets with individual FVLCD floor impaired first; Step 2 remaining shortfall ab
Check your remaining ifrCoworker credits without consuming any. Returns creditsRemaining, creditsUsedToday, fullAccess flag, and a cost estimate for batch calls. FREE — does not decrement quota. Call
Compute a multi-period amortisation / depreciation / EIR amortisation schedule by rolling reportingDate forward one period at a time. Supported standards: ias16 (PPE depreciation), ias38 (intangible a
Generate a structured audit working paper JSON from one or more prior ifr_calculate results. Aggregates across standards: accounting policies (IAS 1.117), key estimation uncertainties (IAS 1.125), cal
Retrieve the calculation-sheets workbook for a prior ifr_calculate or ifr_period_end_batch call. Returns a downloadUrl for the XLSX workbook (GET /api/ifrcoworker/calculation-sheets/{correlationId} wi