56
/ 100
1 month ago
glama

FDIC BankFind MCP Server

Provides programmatic access to the FDIC BankFind Suite API, enabling users to query public data on FDIC-insured financial institutions, bank failures, and branch locations. It supports advanced filtering for financial reports, demographics, and institutional history without requiring an API key.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
2 flows detected: GITHUB_TOKEN. We can’t prove the destination matches the brand the credential belongs to.
🚨
Known vulnerabilities in dependencies: 1 critical, 18 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 3 credentials: FRED_API_KEY, GEMINI_API_KEY, GITHUB_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical18 high15 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@3.2.4GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

high@modelcontextprotocol/sdk@1.0.0GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.0.0GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.7.0GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.7.0GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configALLOWED_ORIGINSBrowser-origin requests are checked against . If unset, the server allows the local defaults for localhost and 127.0.0.1 on the configured port, plus non-browser requests with no Origin header.
configBUILD_VERSION
configCHAT_ALLOWED_ORIGINS
configDOCS_LATEST_RELEASE_OUTPUT
configFDIC_MAX_RESPONSE_BYTESSet to override the upstream FDIC response-size guard. The default is 5242880 bytes (5 MiB).
configFDIC_MCP_PROFILE
configFDIC_MCP_STATELESS_HTTP
🔐 secretFRED_API_KEY
🔐 secretGEMINI_API_KEY
configGITHUB_API_URL
configGITHUB_OUTPUT
configGITHUB_REPOSITORY
🔐 secretGITHUB_TOKEN
configHOSTLocal HTTP runs bind to 127.0.0.1 by default. Set if you intentionally want a different bind address.
configPORTTRANSPORT=http =3000 node dist/index.js
configTRANSPORThttp PORT=3000 node dist/index.js
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/jflamb-fdic-mcp-server-uztqio)](https://m8ven.ai/mcp/jflamb-fdic-mcp-server-uztqio)
commit: 6f7f8bc86441b87c832c39b7cd2dccdfce8512e9
code hash: e69fd67d8d23d4b097fb770f19dd4cc3177f23727ac85568b503b4883a02f753
verified: 6/14/2026, 11:18:11 AM
view raw JSON →