Security

11 tools reviewed

7
bankmcp Review 2026 — A Self-Hosted, Read-Only MCP Server That Lets Your AI Read Your Own Bank Accounts

bankmcp (created September 7, 2026, MIT, 160+ stars in two days) is a small self-hosted MCP server that lets your AI assistant read your own bank accounts over the standard Model Context Protocol. It connects to your banks through Enable Banking — one PSD2 API wrapping 2,700+ European banks — and exposes them to any MCP client (Claude, Claude Code, Cursor, ChatGPT, Ollama and others) as a connector. Read-only by design: no payments, no third party holding your data, one user, and the server itself stores no balances or transactions and sends no telemetry. Ask questions like 'Has the invoice from Acme been paid?', 'What did we spend on groceries in August?' or 'Which subscriptions am I paying for, and what do they cost per year?' This review covers the architecture (your assistant talks to your server, your server talks to Enable Banking via JWT, Enable Banking talks to your bank via PSD2), the two deployment paths (on your own machine for desktop MCP clients with nothing to deploy and no password, or on a small server for claude.ai and phone access), the Enable Banking restricted production mode that allows accessing your own accounts without a commercial contract, the 180-day consent lifecycle with in-conversation renewal, the honest caveats (bank logins happen at your bank's site through Enable Banking's licensed hop, and the localhost certificate warning), and who should care about giving an AI read access to their own finances.

7.6
geiger Review 2026 — One Read-Only Command That Shows What Every AI Agent on Your Machine Can Touch

geiger (created September 6, 2026, MIT, ~100 stars) is a read-only scanner that inventories every AI agent, harness, MCP server, plugin and AI extension installed on a machine and labels what each one can touch. This review covers the ecosystems it detects, the exposure labels (EXECUTES, HOLDS-SECRETS, BROAD-FILESYSTEM, BROAD-WEB, NETWORK), the three promises (read-only, no telemetry, secrets by shape only), the baseline-diff drift alarm built for cron and CI, where it recognises policy wrappers, and its honesty about limits: it reads configuration, not runtime behaviour, and origin is not trustworthiness.

7.5
reverify Review 2026 — A Lie Detector for AI Reverse Engineering That Checks Every Claim Against the Real Bytes

reverify is an MIT-licensed Python toolkit (created 2026-08-31, 740+ stars and a remarkable 152 forks in four days) that stops AI agents from hallucinating when they read binaries. The model proposes; a deterministic PE/ELF/Mach-O toolkit decides — every claim about offsets, structs, instructions or behavior is checked against the actual bytes and returned as VERIFIED, REFUTED or INCONCLUSIVE with evidence. On 19 real Windows system files the repo's reproducible benchmark caught the AI's textbook answer 100% of the time with zero false alarms. It ships as a CLI and an MCP server for Claude Code and Cursor, adds information-weighted scoring so 'grounded' means informative rather than trivially true, and since v0.8.0 keeps a per-binary ledger of verified and refuted facts that survives context compaction. This review covers the verification loop, the version history (v0.3–v0.8 in four days), the honest limits, and who should use it.

7.6
Watermark-Remover Review 2026 — Stripping Multi-Vendor AI Watermarks After the MS Paint GUID Scandal

Watermark-Remover is an MIT-licensed agent skill + stdlib Python service that strips invisible AI provenance marks — C2PA, EXIF/XMP, invisible Unicode, and statistical text watermarks — from PNG, JPEG, PDF, DOCX, MP4, and 20+ more formats. We review it against the MS Paint invisible GUID watermark story (501 points, ~200 comments on HN) and test its layer-based cleaning model, hook-based auto-clean, and the privacy questions the whole category raises.