Access Well financial data including invoices, companies, and contacts.
Do not connect
A critical issue was found. Do not connect this server as-is.
Scanned 7 days ago Due for re-check
A server can change after it's graded. Re-run the automated scan to refresh this report.
This grade is deterministic and reproducible: the same server surface always yields the same grade under a given algorithm version. It is a real automated assessment computed by the MCPGrade engine from what the probe actually observed — not a fabricated or opinion score. It is not a manual human pentest, so it can miss context-specific risks.
Every signal below was measured directly by the automated probe. The grade is derived only from evidence like this — nothing is assumed.
The well-financial-mcp MCP server exposes 33 tools, focused primarily on database and web capabilities. Its published description reads: "Access Well financial data including invoices, companies, and contacts". It communicates over Streamable HTTP using the 2025-06-18 protocol revision, and does not require authorization to connect. MCPGrade currently rates well-financial-mcp F — a critical issue was found and the server should not be connected as-is. Its most notable findings include "Hidden instructions in a tool description" and "Data-exfiltration parameters". This report is a deterministic, reproducible automated assessment: the same observed surface always yields the same grade under a given algorithm version, and it is refreshed as new scans arrive and free to read — but it is not a substitute for a manual human security review. Always re-check well-financial-mcp's advertised tools, transport security, and authorization posture before connecting an autonomous agent or sharing sensitive context with it.
Add well-financial-mcp to an MCP client using the endpoint below. Review the grade and findings above before granting an autonomous agent access.
MCP endpoint
https://api.wellapp.ai/v1/mcpStreamable HTTP transport. This is the MCP endpoint, not a website — paste it into your MCP client server list rather than a browser.
Captured passively during the read-only scan. Click any value to find servers that match it.
The tools this server advertises via tools/list — names, purposes, and the parameters each accepts, exactly as enumerated read-only.
Discover available data types and fields. USAGE: - well_get_schema() → List ALL available roots, including the accounting graph (ledger_accounts, journals, journal_entries) plus account_balances, tax_
Query records from Well's database. ⚠️ WORKFLOW: 1. To SHOW the user a table of a record type, just omit `fields`. You never choose columns for presentation: the table the user sees is ALWAYS the root
Sorted worst-first. Each finding shows its severity, what it means, its OWASP MCP Top-10 mapping, and a recommended fix — the check id links to the exact methodology row that produced it.
tool: well_list_counterparties
A tool description contains imperative text aimed at the model (e.g. "ignore previous", "before answering read …").
not change it; do not tell the user otherwise. This tool only reads. It cRecommendationRemove model-directed instructions from tool descriptions.
tool: well_get_schema
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
tools when the token authorizes more than one workspace.","type":"stRecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_get_schema
A tool description tries to alter the model’s use of another tool.
reconstructing them from raw invoices - well_get_schema({ root: "invoices"RecommendationDescriptions must describe only their own tool.
tool: well_query_records
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
ent_means, chat_conversations, blueprint_runs, workspace_connector_sync_logsRecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_query_records
A tool description tries to alter the model’s use of another tool.
question, call well_get_schema(root) FIRST to discover available fields, thRecommendationDescriptions must describe only their own tool.
tool: well_create_company
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_create_person
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_update_company
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
tools when the token authorizes more than one workspace.","type":"stRecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_update_company
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_update_person
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
tools when the token authorizes more than one workspace.","type":"stRecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_update_person
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_delete_company
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_delete_person
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_update_invoice
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
parameter "billing_context"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_update_invoice
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_delete_invoice
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_add_contact_channel
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
tools when the token authorizes more than one workspace.","type":"stRecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_add_contact_channel
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_remove_contact_channel
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_get_entity
A tool description tries to alter the model’s use of another tool.
onvenience over well_get_schema + well_query_records: resolves the field pathsRecommendationDescriptions must describe only their own tool.
tool: well_list_connector_tools
A tool description tries to alter the model’s use of another tool.
put schema). 3. well_invoke_connector_tool({ workspace_connector_id, tool, args }) → run oRecommendationDescriptions must describe only their own tool.
tool: well_invoke_connector_tool
A tool description tries to alter the model’s use of another tool.
wn list/read tools. WORKFLOW: 1. well_list_connectors() → pick the ENABLERecommendationDescriptions must describe only their own tool.
tool: well_create_invoice_from_data
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
tools when the token authorizes more than one workspace.","type":"stRecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_create_invoice_from_data
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_list_connectors
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_run_register_diff
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_resolve_reconciliation_task
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_resolve_register_diff_gap
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
tools when the token authorizes more than one workspace.","type":"stRecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_resolve_register_diff_gap
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_get_investment_holdings
A tool description tries to alter the model’s use of another tool.
dinary rows via well_query_records on the transactions root instead.RecommendationDescriptions must describe only their own tool.
tool: well_get_runway
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
er's authorized token, same as every other well_* tool). {"$schema":"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_get_runway
A tool description tries to alter the model’s use of another tool.
computing runway yourself from raw account/transaction reads. Returns `caRecommendationDescriptions must describe only their own tool.
tool: well_get_cash_position
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
o reconstructed history, so make a trend claim only when it is present.RecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_get_cash_position
A tool description tries to alter the model’s use of another tool.
t balances yourself. Returns `amount`/`currency` (the converted total), `RecommendationDescriptions must describe only their own tool.
tool: well_get_cost_structure
A tool description tries to alter the model’s use of another tool.
transactions yourself. Returns `entries` (an array of `{ category, amounRecommendationDescriptions must describe only their own tool.
tool: well_create_invoice_document
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
tools when the token authorizes more than one workspace.","type":"stRecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_create_invoice_document
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_create_invoice_document
One tool reads private data, ingests untrusted content, AND can send data outbound — the three preconditions for autonomous data theft in a single call. A prompt injection reaching this tool can exfiltrate secrets with no further step.
, `signed_url` (opens it), and `app_url` (the document in Well). Hand the user `download_url` when theRecommendationSplit the capabilities across separate least-privilege tools so no single tool can read secrets, read untrusted input, and reach the network at once.
tool: well_list_missing_invoices
A tool exposes a free-text/webhook/feedback parameter with no honest purpose — a classic exfil channel.
er's authorized token, same as every other well_* tool). {"$schema":"RecommendationRemove side-channel parameters; constrain tool inputs.
tool: well_list_missing_invoices
A tool description tries to alter the model’s use of another tool.
d this session (well_list_periods → the user clicks → well_switch_workspace recorRecommendationDescriptions must describe only their own tool.
tool: well_list_periods
A tool description tries to alter the model’s use of another tool.
nth — the rows `well_list_missing_invoices` would return. 0 whenever invoice_state is "nonRecommendationDescriptions must describe only their own tool.
tool: well_preview_invoice_fetch
A tool description tries to alter the model’s use of another tool.
d this session (well_list_periods → the user clicks → well_switch_workspace recorRecommendationDescriptions must describe only their own tool.
tool: well_switch_workspace
A tool description tries to alter the model’s use of another tool.
RecommendationDescriptions must describe only their own tool.
tool: well_list_counterparties
A tool description tries to alter the model’s use of another tool.
e scope ONE way: - `periods: [{ calendar_year, calendar_month }, …]` (1-12RecommendationDescriptions must describe only their own tool.
tool: well_wait_for_selection
A tool description tries to alter the model’s use of another tool.
user to click: well_list_workspaces (kind "workspace"), well_list_periods (kind "peRecommendationDescriptions must describe only their own tool.
The server accepts tool enumeration (and likely invocation) with no authentication.
RecommendationRequire OAuth 2.1 authorization for any server exposing non-public tools.
tool: well_update_company
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: well_update_person
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: well_delete_company
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: well_delete_person
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: well_update_invoice
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: well_delete_invoice
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: well_remove_contact_channel
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: well_invoke_connector_tool
The server advertises open-world / broadly-scoped capabilities.
annotations.destructiveHint = trueRecommendationScope tools to the minimum needed.
tool: well_create_invoice_document
One tool both accesses the filesystem and reaches the network. Combining two capability classes in a single tool widens its blast radius and is the substrate for confused-deputy and exfiltration abuse.
where — it only creates and attaches the file. REQUIRED: invoice_id (the invoice must alreadRecommendationSeparate filesystem and network capabilities into distinct, independently-scoped tools.
tool: well_query_records
An unusually long description is a common injection-padding tactic.
description length 6375 charsRecommendationKeep descriptions concise.
tool: well_list_connectors
An unusually long description is a common injection-padding tactic.
description length 4479 charsRecommendationKeep descriptions concise.
tool: well_list_missing_invoices
An unusually long description is a common injection-padding tactic.
description length 2689 charsRecommendationKeep descriptions concise.
tool: well_list_periods
An unusually long description is a common injection-padding tactic.
description length 3068 charsRecommendationKeep descriptions concise.
tool: well_preview_invoice_fetch
An unusually long description is a common injection-padding tactic.
description length 2522 charsRecommendationKeep descriptions concise.
tool: well_list_counterparties
An unusually long description is a common injection-padding tactic.
description length 2059 charsRecommendationKeep descriptions concise.
The server exposes one or more ui:// (MCP Apps) resources whose HTML/JS renders inside the host client — a client-side injection / data-exposure surface most scanners ignore. Flagged for review, not damning on its own.
1 ui:// resource(s); e.g. ui://well/widget/856bffe9RecommendationReview each ui:// resource’s markup and scripts; treat host-rendered UI as untrusted, sandbox it, and never expose secrets or conversation context to it.
Vantaj uptime monitoring via MCP — manage monitors, heartbeats, incidents, and status pages.
Unified gateway to Algeria's TKAWEN ecosystem: commerce, certification, and AI tools.
Provides access to the Cohereon Doctrine AI safety framework with governance components, tiered access, and agent onboarding.
Agentic rails for complex workflows with receipts, fees, and MCP tool access.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Structural TC39 spec lookup for ECMA-262 and ECMA-402 in AI agents, SHA-pinned and offline-first.
Create a new company in the current workspace. Use this tool when the user asks to create, add, or register a new company. REQUIRED: name OPTIONAL: description After creation, enrichment (logo, domain
Create a new person (contact) in the current workspace. Use this tool when the user asks to add, create, or register a new contact, employee, or person. REQUIRED: first_name OPTIONAL: last_name, job_t
Update an existing company in the current workspace. Use this tool when the user asks to change, fix, rename, or edit a company's fields. REQUIRED: company_id OPTIONAL (only include fields the user wa
Update an existing person (contact) in the current workspace. Use this tool when the user asks to change, fix, rename, or edit a person's fields. REQUIRED: person_id OPTIONAL (only include fields the
Delete a company from the current workspace (soft delete). Use this tool when the user asks to delete, remove, or archive a company. REQUIRED: company_id This soft-deletes the company and its company_
Delete a person (contact) from the current workspace (soft delete). Use this tool when the user asks to delete, remove, or archive a contact. REQUIRED: person_id This soft-deletes the person and its c
Update an existing invoice in Well. Call well_get_schema("invoices") to discover all available fields. REQUIRED: invoice_id OPTIONAL (only pass fields you want changed): - reference_number, issue_date
Delete an invoice from Well (soft delete). REQUIRED: invoice_id Soft-deletes the invoice. Linked line items and payment_means rows are NOT cascade-deleted — they remain in the database, orphaned. The
Add a contact channel to a company or person. Wraps the resource-scoped REST endpoints (POST /v1/{companies,people}/:id/{emails,phones,web-links,locations}). channel + the matching value field: - emai
Remove a contact channel from a company or person. Wraps the resource-scoped DELETE endpoints (DELETE /v1/{companies,people}/:id/{emails,phones,web-links,locations}/:channelId). Pass channel_id = the
Read ONE entity with its sub-resources nested in a single call. Convenience over well_get_schema + well_query_records: resolves the field paths for you and returns the single record with its related d
Discover the actions a connected provider exposes (e.g. "what can I do with Attio?"). WORKFLOW: 1. well_list_connectors() → pick the ENABLED provider (connection_status: "enabled") and read its worksp
Run one tool on a connected provider's own MCP server (e.g. create a record in Attio), on behalf of this workspace's connection. Use this ONLY for an action the user explicitly asked to take on that p
Create an invoice in Well from data you extracted by reading an invoice (your own OCR) — you send the structured fields, not the file. Well persists the invoice + its line items + payment means using
List the workspaces this connection is authorized to access. Use this FIRST when a single token may cover more than one workspace. Each entry has: - workspace_id: pass this as the workspace_id argumen
List the connectors a workspace can install AND everything it has already connected, each with a one-click install deep link. ONE tool answers both halves of the connect question — "what can I connect
Diff a workspace's bank transactions against its accounting-register transactions (e.g. QuickBooks), and persist the result. - Every match — hard evidence (structured reference, IBAN, tax ID) or infer
Approve or reject one or more reconciliation review tasks (from well_run_register_diff or the in-app review queue). - approve: confirms the match — the link is flipped to active. - reject: dismisses t
Post a well_run_register_diff gap (one of missing_in_register_ids' review tasks) into QuickBooks as a Purchase or Deposit. Requires the exact ledger_account_id (a UUID, not a name) for both: - bank_le
Get the live holdings/positions (what's currently held and its value) for a connected Plaid investment account — brokerage, IRA, 401k, etc. WORKFLOW: 1. well_list_connectors() → pick the ENABLED Plaid
Get the workspace's current cash runway — cash on hand, trailing-3-month average burn, and months of cash left — the exact same computation and numbers the Well app's canvas KPI cards show. Use this i
Get the workspace's current cash position: total cash on hand right now, converted to the workspace base currency, plus a per-account breakdown — the exact same computation and numbers the Well app's
Get the workspace's cost structure: outflow for the latest closed month, broken down by category — the exact same computation and numbers the Well app's canvas cost-structure donut chart shows. Use th
Render an existing invoice as a print-ready PDF and attach it as the invoice's source document. The letterhead carries the issuing company's own mark when Well has one on file, and otherwise sets the
Get which company the workspace itself is: the confirmed own-company anchor (`anchor`) and any detected companies not yet confirmed as it (`candidates`). Use this whenever a question turns on "mine" v
List the supplier invoices a past period is still missing — the settled spend whose invoice has not been collected, one row per counterparty, exactly as the Well app's expense-invoices card shows them
List the recent accounting months of the workspace, with each month's close status, its invoice-retrieval state, and the counts that describe how much work it holds. Use this to ask the user WHICH mon
Preview which invoice agents a past period WOULD launch to collect its missing supplier invoices, and what the rest of the gaps would need instead. Use it for "what would happen if I fetched <month>'s
Write this connection's session context — the one place a conversation's standing choices live. This is the tool the widget cards call when the user CLICKS them: the workspace pin and queue, the selec
List the workspace's counterparty companies and how each one is CATEGORIZED — the company-level industry labels a counterparty carries. Use it for "which suppliers have no category?", "what industries
Read the user's card click — returns instantly if they already clicked; otherwise waits briefly. Call it after the tool whose card asks the user to click: well_list_workspaces (kind "workspace"), well