agentsclimarketplace

Setup

Skill ya5huk/findash/skills/setup

An Israeli Claude Finance Plugin

Install
npx -y skills add ya5huk/findash --skill setup

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 20 stars20 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Use when the user says "set up findash", "onboard", "first-time setup", "get findash running", "configure findash", or is installing the plugin for the first time. Runs findash-doctor's safe auto-fixes, then guides the human through the steps only they can do — creating `.secrets/findash`, the rclone Google Drive OAuth, the Telegram bot, and the one-time bank-scraper browser seeding.

SKILL.md

5.9 KB, as published. Nobody here has run it

setup

First-time onboarding for findash. You automate everything safe and local, then guide the human through everything that needs them. You never enter the user's secrets yourself and never run anything that captures their passwords through this session — you tell them exactly what to put where, and they do it.

Steps

1. Run the doctor's auto-fixes

Run the findash-doctor skill (diagnose → auto-fix → report). It creates data/ inbox/ output/ .secrets/, fixes file modes, runs npm install, bundles the vendor assets, and inits the DB. Read its report: the 🚫 Blockers and ⚠️ Optional lines are exactly the steps below that the human still has to do. See ../findash-doctor/SKILL.md.

2. Secrets — one file, filled in by the user

Tell the user to create .secrets/findash and chmod 600 it. Give them this single block to paste and edit — they keep only the sections they need:

# .secrets/findash — chmod 600. Omit any section you don't use.
[drive]
root_folder_id=<from your vault folder's Drive URL: drive.google.com/drive/folders/<ID>>

[hapoalim]
user_code=<your hapoalim user code>
password=<your hapoalim password>

[cal]
username=<your cal username>
password=<your cal password>

[telegram]
bot_token=<from @BotFather>
chat_id=<your numeric id, from @userinfobot>

[pdf-passwords]
<payslip-filename-pattern>=<password>

[ibkr]
# IBKR auth is the official Interactive Brokers connector you add in Claude (no
# password here). The account IBKR maps onto is resolved automatically by
# /findash:fetch-investments and stored in the DB — nothing to set here.
# account_name=<legacy override only — pre-existing installs>
# account_ids=<comma-separated IBKR account ids>
# base_currency=ILS

Then: chmod 600 .secrets/findash.

Do not collect these values in the conversation or write the file yourself — the user pastes their own secrets in. rclone's OAuth token lives separately in rclone.conf (step 3), not here.

Coming from the old per-file layout? Legacy .secrets/{drive,hapoalim,cal,telegram,pdf-passwords} files are no longer read. Tell the user to copy each value into the matching [section] of .secrets/findash and delete the old files — until they do, that integration won't work. Don't move their secrets for them.

3. Steps only the human can do

These need a browser or an interactive terminal — you cannot do them, so print the exact commands and let the user run them:

  • rclone Google Drive OAuth: rclone config to authorize Drive, then make sure the token ends up at ./rclone.conf (chmod 600). doctor moves ~/.config/rclone/rclone.conf./rclone.conf automatically if it finds it there. Drive powers manual-drop ingest + the weekly DB backup; without it the daily flow still runs degraded (bank fetch + dashboard), so this step can be deferred.
  • Telegram bot (only if you want delivery): create a bot via @BotFather/newbot, tap Start so it can DM you, then put bot_token + chat_id in .secrets/findash [telegram].
  • Bank-scraper browser seeding (only if you use fetch): one interactive run per source to seed the trusted-device cookie:
    node scripts/fetch_bank.js --company=hapoalim --setup
    node scripts/fetch_bank.js --company=visaCal --setup
    
    Log in, complete OTP / CAPTCHA, trust the device, then press Enter. The profile is saved under ~/.cache/findash/chromium-profile/<companyId>/ and reused silently afterward.
  • IBKR portfolio (only if you use Interactive Brokers): IBKR is not a findash MCP server — it's Anthropic's official Interactive Brokers connector, added through Claude's own connector directory. Its auth is interactive-only, so the daily run attempts it best-effort and unattended runs skip it with a warning.
    1. Add the connector once: in Claude, +ConnectorsAdd connectorBrowse connectors, search "ibkr", pick Interactive Brokers (IBKR) (under Anthropic & Partners), and log in with your IBKR credentials. Confirm with /mcp (Interactive Brokers (IBKR) · connected), and restart Claude Code so the session picks it up.
    2. Account mapping is automatic. fetch-investments resolves which findash account IBKR feeds (attaching to an existing broker when the ledgers clearly match — some brokers are IBKR wrappers underneath — creating one for IBKR-only users, asking only when genuinely ambiguous) and persists the choice in the DB. There is nothing to configure by hand.
    3. Pull your trades: run /findash:fetch-investments in an interactive session. It ingests your IBKR trade history onto the mapped account (so you stop screenshotting trades) plus a reconciliation snapshot. It's read-only — deny any tool that would place an order or move funds. The account it maps onto is resolved automatically (see step 2). If you don't use IBKR, skip this entirely.

4. Re-run the doctor

Run findash-doctor again and confirm it reports all-systems-go (or only optional gaps for features the user doesn't want). Point the user at docs/setup.md for the full reference.

Principles

  • You automate the safe, local, idempotent work; the human owns secrets and OAuth. Never type the user's passwords / tokens for them, never run rclone config or any --setup on their behalf (these need a human at a browser), never print secret values.
  • One secrets file. .secrets/findash is the only place findash reads credentials from — there is no per-file fallback.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.