Borrowing it
Nothing to install: this file belongs to hs737/mcp-server-for-ynab. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/hs737/mcp-server-for-ynab/master/.agents/skills/ynab-platform-compliance/SKILL.mdgit clone --depth 1 https://github.com/hs737/mcp-server-for-ynabWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/hs737/mcp-server-for-ynab/ynab-platform-compliance)<a href="https://agentmods.dev/skills/hs737/mcp-server-for-ynab/ynab-platform-compliance"><img src="https://agentmods.dev/badge/skills/hs737/mcp-server-for-ynab/ynab-platform-compliance/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/hs737/mcp-server-for-ynab/ynab-platform-compliance"><img src="https://agentmods.dev/badge/skills/hs737/mcp-server-for-ynab/ynab-platform-compliance.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00028 | $0.01222 |
| Opus 5 | $0.00014 | $0.00611 |
| Sonnet 5 | $0.00006 | $0.00244 |
| Haiku 4.5 | $0.00003 | $0.00122 |
Grade A, and why
ynab-platform-compliance scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 121 lines — stays where its author put it; the contents beside it link to each section on GitHub.
YNAB Platform Compliance
YNAB publishes binding requirements for applications built on their API. Some constrain things that are expensive to change later — the project name, the DNS name, what a privacy policy must say. Check this skill before naming anything, before publishing, and before any hosted or OAuth work.
Source: https://api.ynab.com/#oauth-requirements. Re-read it when the answer matters; the requirements below were captured from that page and may have moved.
Use When
- Naming or renaming the project, package, binary, repository, or a domain
- Writing README, site, or docs copy that mentions YNAB
- Adding branding, logos, or a "Works with YNAB" badge
- Any work toward OAuth, hosting, or multi-user
- Drafting or revising a privacy policy
- Before publishing to a package registry or announcing the project
Naming — the rule most likely to bite
"The application and the web address (DNS name) must not include 'YNAB' or 'You Need A Budget' unless preceded by the word 'for'."
Acceptable: "Budget Tools", "Transaction Syncer", "Currency Tools for YNAB". Unacceptable: "YNAB Tools", "YNAB Transaction Syncer", "Advanced YNAB".
This project therefore uses:
| Thing | Value |
|---|---|
| Repository and package | mcp-server-for-ynab |
| Server name reported to clients | mcp-server-for-ynab |
| English title | MCP Server for YNAB |
A future domain must follow the same rule: mcp-server-for-ynab.com is fine,
ynab-mcp.com is not. scripts/mcp_http_check.sh asserts the reported server
name complies, and a unit test covers it. Do not weaken either check.
Required disclaimer
This exact text must appear in the site footer, and is currently in README.md
and NOTICE.md:
"We are not affiliated, associated, or in any way officially connected with YNAB or any of its subsidiaries or affiliates. The official YNAB website can be found at https://www.ynab.com. The names YNAB and You Need A Budget, as well as related names, tradenames, marks, trademarks, emblems, and images are registered trademarks of YNAB."
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 121 lines · 28 tokens per session scan A 95e96b5bbb54
ynab-platform-compliance is a skill published in the GitHub repository hs737/mcp-server-for-ynab (1 stars, last pushed 2d ago), licensed Apache-2.0. It adds 28 tokens to every session and 1,222 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
clio-webhooks
Receive and verify Clio (Clio Manage) webhooks. Use when setting up Clio webhook handlers, debugging X-Hook-Signature verification, completing the X-Hook-Secret handshake, or handling legal practice events like matter.created, contact.updated, activity.created, or bill events.
affiliation-map
A company-affiliation map built from Russian business registry records. It links founders, managers, related companies, registration details, and bankruptcy information.
contract-review-workflow
Trigger a deployed Mistral Workflow for contract review, poll execution status, detect human-in-the-loop checkpoints via workflowinteract(query), collect approval or changes, and resume the workflow via workflowinteract(signal). Use when the user wants to run a contract through a Mistral Workflow with oversight…
agoragentic-govern
Apply Agoragentic local governance before an agent performs side effects. Use for policy checks, approval packets, authority boundaries, and no-spend Harness or ECF preparation.
procure-quotazioni
Genera in serie procure alle liti (art. 83 c.p.c.) e lettere di quotazione compensi D.M. 55/2014 in DOCX per posizioni di recupero crediti, partendo da un Excel di posizioni o dai dati forniti, con rilevamento della fase processuale (monitorio, esecuzione forzata, opposizione a decreto ingiuntivo). Usa quando l'utente…
analisi-sinistro
Analizza sinistri stradali, sanitari e lavorativi con quantificazione del danno non patrimoniale (unitario, ex art. 2059 c.c.), rivalutazione ISTAT e interessi compensativi. Usa quando l'utente descrive un incidente, un sinistro, chiede risarcimento danni per invalidita o quantificazione danni da lesioni personali.