Local MCP server for korean-jangbu-for skill package - Korean personal finance ledger management with OCR, transaction classification, and reporting
Server has 15 tools with mostly complete schemas and descriptions in Korean. Naming is consistently verb-prefixed (ingest_, ocr_, list_, get_, classify_, apply_, export_, codef_*). Schemas are properly structured with required fields and enums. However, parameter descriptions are sparse or missing for several tools; output schemas are undocumented; error handling guidance is absent; and no tool annotations (readOnlyHint/destructiveHint) are present. Most tools lack detail on what they return, making it difficult for LLMs to plan downstream calls. Security-sensitive tools (codef_fetch_hometax, codef_fetch_bank) lack explicit notes on credential handling and side effects.
분류 결과 저장. source는 rule/llm/user 중 하나.
룰 기반으로 거래를 일괄 분류. 성공 건은 바로 저장. 실패 건 ID 리스트 반환.
CODEF Client ID / Secret / (선택)공개키 저장. 기본 Keychain, 실패 시 ~/.jangbu/credentials.env(권한 0o600). 외부 전송 없음.
CODEF 자동 수집 자격증명 등록 상태 확인. 키는 마스킹되어 프리뷰만 반환.
CODEF 경유 은행 거래내역 자동 수집. 15개 은행 지원. 간편인증/ID-PW 사용.
CODEF 경유 카드 이용내역 자동 수집. 9개 카드사 지원.
CODEF 경유 홈택스 자동 수집 — 소득금액증명·납세증명·사업자등록증명 등. 간편인증 2단계 필요.
Output schemas are not documented for any tool. LLMs cannot plan downstream tool calls or understand what fields to extract. For example, list_transactions returns 'masked transaction list' but the structure (fields, types, pagination) is not declared.
Security-sensitive tools (codef_credentials_save, codef_fetch_hometax, codef_fetch_bank, codef_fetch_card) do not declare their permission requirements or explicitly state that they modify state and have side effects. Descriptions lack warnings about irreversibility.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | D | 59 | 2026-07-28+ | v2 |
더존·세무사랑 호환 분개 CSV 출력. 세무사 전달용. 국세청 표준계정 + 부가세 간이 분리. 언마스킹 원본 기반, 로컬 파일만.
BS/PL/현금흐름/cash burn 리포트를 로컬 파일로 생성. 언마스킹된 데이터 사용, 파일은 ~/.jangbu/reports/ 에만 저장.
감사 로그 조회
단건 거래 마스킹 뷰 반환.
엑셀/CSV 파일을 표준 거래내역으로 파싱해 SQLite에 적재. LLM에 원본을 노출하지 않음.
거래내역 목록을 마스킹된 뷰로 반환. LLM 전달 전용.
OCR 파싱 후 unparsed 패턴 분석 + 가맹점·카드 식별자 alias 제안. Level 2 준수 — 거래 내역 금액·사업자번호 등은 요약에 포함 안함. 결과를 사용자에게 보여주고 동의 시 ocr_apply_alias로 적용.
영수증·세금계산서·통장 스캔·카드명세서(PDF)를 PaddleOCR(로컬)로 처리. 구조화까지 수행. card_statement_scan은 신한카드 포맷 우선 지원.
Tool descriptions lack WHEN to use guidance and differentiation from similar tools. For example, list_transactions vs get_transaction_masked should explain use cases. codef_fetch_hometax vs codef_fetch_bank are both fetch operations but the decision logic is missing.
Parameter descriptions are missing or minimal for several tools. codef_fetch_hometax has 'twoway_info' parameter with description '2단계 호출 시 전단계 twoWayInfo 그대로' (opaque; no actionable guidance on structure). codef_fetch_bank 'account_password' lacks format guidance. codef_credentials_status has zero parameters but no description of what status looks like.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint) are present. LLMs cannot distinguish read-only tools (list_transactions, get_transaction_masked, export_report) from write tools (ingest_raw, ocr_document with auto_ingest=true, codef_fetch_*). This violates current MCP spec (2026-07-28) tool annotation pattern.
No error recovery guidance. Tools like codef_fetch_hometax require '2단계 간편인증' (2-step simple auth) but there is no documented error scenario for failed auth, missing credentials, or invalid identity format. LLMs will not know how to retry or what to ask the user.
Pagination not documented. list_transactions accepts 'limit' (default 100) but no next_cursor, page, or total_count is mentioned. Large datasets will truncate silently, and LLMs have no way to fetch subsequent pages.
get_audit_log has empty parameter schema and minimal (40 char) description. Its purpose, return format, and filtering options are completely undocumented.
ocr_document parameter 'auto_ingest' defaults to true, which is a state-modifying side effect. If an LLM calls this tool without explicitly setting auto_ingest=false, it will automatically ingest (persist) transactions. The description mentions this is possible but does not warn against accidental ingestion.