Skip to content

Upgrade to ynab SDK v4, add new tools, fix version/coverage/security - #6

Merged
auzroz merged 2 commits into
mainfrom
claude/determined-hopper-xt3sm2
Jun 30, 2026
Merged

auzroz merged 2 commits into
mainfrom
claude/determined-hopper-xt3sm2

Conversation

@auzroz

@auzroz auzroz commented Jun 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

A review pass over the server plus the approved ynab SDK v4 upgrade. The SDK jump is an internal-only refactor (the Budget→Plan rename); MCP tool names, parameters, and output shapes are unchanged, so existing clients are unaffected. New tools are purely additive. Version bumped to 0.2.0 accordingly.

Dependencies

  • ynab ^2.10.0 → ^4.4.0. Internal migration: api.budgets→api.plans, getBudget*→getPlan*, Budget*Response types → Plan*Response, and the three response-shape consumers updated (.data.budgets→.data.plans, .data.budget→.data.plan).
  • @modelcontextprotocol/sdk ^1.25.3 → ^1.29.0, resolving a HIGH-severity cross-client data-leak advisory. npm audit fix took advisories 19 → 5; the remaining 5 are dev-only (vitest/vite/esbuild) and are not shipped.

New tools (59 → 66)

Write (gated by YNAB_READ_ONLY=false): ynab_update_payee, ynab_create_payee, ynab_create_category, ynab_create_category_group, ynab_update_category_group, ynab_update_transactions (bulk). Read: ynab_list_money_movements. Each write tool follows the existing audit-log + cache-invalidation + read-only-guard pattern.

Fixes

  • Server now reports its real version to MCP clients (was hardcoded 0.1.0; reads package.json).
  • Re-enabled the Vitest coverage gate — the threshold used the pre-1.0 thresholds.global.* shape that Vitest 1.x silently ignored. Now enforced as a floor.
  • ynab_create_account now offers only the account types the YNAB API can actually create (SaveAccountType); previously-offered loan/mortgage types always failed at the API.
  • Corrected README tool counts/listings (now 66: 40 core API, 23 analytics, 3 system), including previously omitted scheduled-transaction and analytics tools.
  • Replaced the stale, partly-fictional tools list in server.json with the actual registered names; added a version field.
  • Added CHANGELOG.md.

Verification

npm run lint, npm run typecheck, npm run test:coverage (209 tests, gate passes), and npm run build all pass locally. A stdio smoke test confirmed the server advertises 0.2.0 and lists all 7 new tools. The live YNAB API path (budgets→plans round-trip, an actual payee rename) was not exercised — it needs a real YNAB_ACCESS_TOKEN.

🤖 Generated with Claude Code

https://claude.ai/code/session_016PgWfscEzb25EXrgJg1Mt5


Generated by Claude Code

Summary by CodeRabbit

  • New Features

    • Added new write tools for creating and renaming categories and payees, plus bulk transaction updates.
    • Added a new read tool for listing money movements.
    • Expanded supported budget, transaction, and scheduling tool coverage.
  • Bug Fixes

    • Corrected the server’s reported version to match the published release.
    • Fixed tool counts and listings in the README and server metadata.
    • Updated budget data handling to match the latest YNAB API response format.

…urity

Upgrade ynab SDK 2.10.0 -> 4.4.0 (internal budgets->plans rename; MCP tool
surface unchanged) and @modelcontextprotocol/sdk 1.25.3 -> 1.29.0 (clears a
HIGH cross-client data-leak advisory).

New tools unlocked by the v4 surface:
- ynab_update_payee, ynab_create_payee
- ynab_create_category, ynab_create_category_group, ynab_update_category_group
- ynab_update_transactions (bulk)
- ynab_list_money_movements (read)

Fixes:
- Server now reports its real version (was hardcoded 0.1.0; reads package.json)
- Re-enable the Vitest coverage gate (pre-1.0 thresholds.global.* shape was
  silently ignored); enforce as a floor
- create-account now offers only API-creatable account types (SaveAccountType)
- Correct README tool counts/listings and replace the stale, partly-fictional
  server.json tools list with the real registry; add server.json version
- Add CHANGELOG.md

Bump version to 0.2.0 (additive, no MCP-client breaking changes).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PgWfscEzb25EXrgJg1Mt5
@coderabbitai

coderabbitai Bot commented Jun 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@auzroz, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 38 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 38edf6b3-753c-4aec-8eba-2cc52666b16e

📥 Commits

Reviewing files that changed from the base of the PR and between 095d49d and 9c4b2d1.

📒 Files selected for processing (1)
  • README.md

Walkthrough

This PR upgrades the ynab SDK to v4 and MCP SDK, renaming budget-related response fields from budget to plan across client and tool handlers. It adds new write tools (category/category-group/payee create and rename, bulk transaction updates) and a money movements read tool, wires them into the tool registry, and updates server manifest, README, CHANGELOG, and coverage thresholds.

Changes

YNAB v4 migration and new tools

Layer / File(s) Summary
Dependency and version metadata
package.json, src/index.ts, src/server.ts
Bumps ynab and @modelcontextprotocol/sdk versions, package version to 0.2.0, and reports runtime version from package.json instead of a hardcoded string.
Budget-to-plan response shape migration
src/services/ynab-client.ts, src/tools/budgets/*, src/tools/analytics/age-of-money.ts, src/tools/accounts/create-account.ts, src/tools/transactions/{create,update}-transaction*.ts
Switches getBudgets/getBudgetById/getBudgetSettingsById/getBudgetMonth to plan-oriented SDK endpoints and response fields; narrows creatable account types; updates transaction handler type comments/annotations.
Category and category-group write tools
src/services/ynab-client.ts, src/tools/categories/create-category.ts, .../create-category-group.ts, .../update-category-group.ts
Adds client wrappers with write guards, rate limiting, cache invalidation, audit logging, plus new MCP tools to create categories/groups and rename groups.
Payee write tools
src/services/ynab-client.ts, src/tools/payees/create-payee.ts, .../update-payee.ts
Adds createPayee/updatePayee client wrappers with similar write protections plus the corresponding tools.
Bulk transaction update tool
src/services/ynab-client.ts, src/tools/transactions/update-transactions.ts
Adds updateTransactions client wrapper and a new bulk-update MCP tool converting amounts and field types.
Money movements read tool
src/services/ynab-client.ts, src/tools/money-movements/list-money-movements.ts
Adds getMoneyMovements fetch and a new read tool listing money movements with formatting/sanitization.
Tool registry wiring
src/tools/index.ts
Registers new tools and handlers for categories, payees, bulk transactions, and money movements.
Docs, manifest, changelog, test config
server.json, README.md, CHANGELOG.md, vitest.config.ts
Updates server.json tool list/version, README tool counts, adds CHANGELOG entry, and restores enforced Vitest coverage thresholds.

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~60 minutes

Possibly related PRs

  • auzroz/ynab-mcp#1: Both PRs modify src/services/ynab-client.ts write-mode enforcement and src/tools/index.ts tool registry wiring.
  • auzroz/ynab-mcp#2: Both PRs touch src/tools/budgets/get-budget-settings.ts nullable format handling and transaction handler SDK type alignment.

Security Note 🔒

Flagging for visibility: the new write-path wrappers (createCategory, createCategoryGroup, updateCategoryGroup, createPayee, updatePayee, updateTransactions) correctly gate on assertWriteAllowed and redact names in audit logs — good defensive pattern. Worth double-checking that error messages are consistently sanitized before logging across all these new wrappers, and that the YNAB_READ_ONLY flag default is fail-safe (defaults to read-only) so newly added write tools can't be invoked unintentionally in production configs. Also worth confirming server.json's expanded tool list doesn't expose any tool identifiers that aren't actually gated by the same read-only check.

A budget became a plan overnight,
New tools for payees, categories bright,
Bulk edits flow in tidy array,
Coverage gates wake up and stay,
🛡️ guarded writes, audit logs in sight.

🚥 Pre-merge checks | ✅ 5 | ❌ 4

❌ Failed checks (4 inconclusive)

Check name Status Explanation Resolution
No Hardcoded Secrets ❓ Inconclusive Repository clone failed, so this custom check could not run with code access. Retry the review run. If this persists, inspect pre-merge custom-check logs for infrastructure or agent runtime failures.
Input Validation ❓ Inconclusive Repository clone failed, so this custom check could not run with code access. Retry the review run. If this persists, inspect pre-merge custom-check logs for infrastructure or agent runtime failures.
Rate Limit Compliance ❓ Inconclusive Repository clone failed, so this custom check could not run with code access. Retry the review run. If this persists, inspect pre-merge custom-check logs for infrastructure or agent runtime failures.
Error Message Safety ❓ Inconclusive Repository clone failed, so this custom check could not run with code access. Retry the review run. If this persists, inspect pre-merge custom-check logs for infrastructure or agent runtime failures.
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title is clear, concise, and matches the PR’s main scope: SDK v4 upgrade plus new tools and version/coverage fixes.
Docstring Coverage ✅ Passed Docstring coverage is 92.31% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch claude/determined-hopper-xt3sm2

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@package.json`:
- Around line 45-47: Add npm overrides to force patched versions of the
vulnerable transitive dependencies introduced by
`@modelcontextprotocol/sdk`@1.29.0. Update the package.json dependency
configuration so the lockfile resolves safe versions for fast-uri, hono,
ip-address, and express-rate-limit, then regenerate the lockfile to ensure npm
audit --audit-level=high passes.

In `@README.md`:
- Line 19: The README tool-count wording is ambiguous because “66 tools ... plus
23 custom analytics tools” implies an extra 23 beyond the total shown elsewhere.
Update the marketing copy in the README’s “Access everything” line to make clear
that the 23 custom analytics tools are part of the 66 total, and keep the
wording consistent with the “Available Tools (66 Total)” section and the
Features table.

In `@src/services/ynab-client.ts`:
- Around line 938-941: The getMoneyMovements method is calling the wrong YNAB
SDK member, so the request will fail at runtime. Update
YNABClient.getMoneyMovements to use the correct API shape on this.api, replacing
the underscored property access with the camelCase moneyMovements member while
keeping the existing rateLimiter.acquire flow intact.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 43d0783e-0089-4626-940f-2d422c502455

📥 Commits

Reviewing files that changed from the base of the PR and between ccb3037 and 095d49d.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (24)
  • CHANGELOG.md
  • README.md
  • package.json
  • server.json
  • src/index.ts
  • src/server.ts
  • src/services/ynab-client.ts
  • src/tools/accounts/create-account.ts
  • src/tools/analytics/age-of-money.ts
  • src/tools/budgets/get-budget-settings.ts
  • src/tools/budgets/get-budget.ts
  • src/tools/budgets/list-budgets.ts
  • src/tools/categories/create-category-group.ts
  • src/tools/categories/create-category.ts
  • src/tools/categories/update-category-group.ts
  • src/tools/index.ts
  • src/tools/money-movements/list-money-movements.ts
  • src/tools/payees/create-payee.ts
  • src/tools/payees/update-payee.ts
  • src/tools/transactions/create-transaction.ts
  • src/tools/transactions/create-transactions.ts
  • src/tools/transactions/update-transaction.ts
  • src/tools/transactions/update-transactions.ts
  • vitest.config.ts

Comment thread package.json
Comment thread README.md Outdated
Comment thread src/services/ynab-client.ts
The "66 tools ... plus 23 custom analytics" phrasing read as additive
(66+23). Reword to make clear the breakdown sums to 66 (40 core API +
23 analytics + 3 system). Addresses a CodeRabbit review note.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016PgWfscEzb25EXrgJg1Mt5
@auzroz
auzroz merged commit 9bc00b5 into main Jun 30, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants