# get_bank_accounts

Get transparent bank accounts published for this company (only available for VAT-registered subjects). Useful to verify payment details on an invoice match the company.

Agent View of the PolicyLayer registry record for `get_bank_accounts`. HTML page: https://policylayer.com/tools/dev-cz-agents-ares/get-bank-accounts

## Facts

- Tool: `get_bank_accounts`
- Server: Ares (`https://ares.cz-agents.dev/mcp`) — https://policylayer.com/tools/dev-cz-agents-ares.md
- Homepage: https://github.com/martinhavel/cz-agents-mcp
- Risk category: Read (Low risk)
- Registry record: grade C, identity unverified
- Server auth posture: open
- Server rate-limited: yes
- Parameters: 1 (1 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `ico` | string | yes | Czech IČO (7-8 digits). |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_bank_accounts",
    "arguments": {
      "ico": "<ico>"
    }
  }
}
```

## Why get_bank_accounts is rated Low

This tool retrieves and queries publicly published financial data from a transparent accounts registry. It performs a read-only lookup operation with no capability to modify, delete, or execute code. The data retrieved is already public and published by the Czech Business Register. The use case described—verifying payment details on invoices—is a verification/lookup task.

From the tool's own definition: "Tool name and description indicate retrieval of publicly available bank account information: 'Get transparent bank accounts published for this company' and 'only available for VAT-registered subjects'."

## Use case

AI agents call get_bank_accounts to retrieve information from Ares without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Ares:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "get_bank_accounts": {}
  }
}
```

## Other tools on Ares (9)

- `check_vat_payer` — Read — https://policylayer.com/tools/dev-cz-agents-ares/check-vat-payer.md
- `get_history` — Read — https://policylayer.com/tools/dev-cz-agents-ares/get-history.md
- `get_statutaries` — Read — https://policylayer.com/tools/dev-cz-agents-ares/get-statutaries.md
- `lookup_by_ico` — Read — https://policylayer.com/tools/dev-cz-agents-ares/lookup-by-ico.md
- `search_by_address` — Read — https://policylayer.com/tools/dev-cz-agents-ares/search-by-address.md
- `search_by_nace` — Read — https://policylayer.com/tools/dev-cz-agents-ares/search-by-nace.md
- `search_companies` — Read — https://policylayer.com/tools/dev-cz-agents-ares/search-companies.md
- `validate_dic` — Read — https://policylayer.com/tools/dev-cz-agents-ares/validate-dic.md
- `watch_entity` — Write — https://policylayer.com/tools/dev-cz-agents-ares/watch-entity.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=dev-cz-agents-ares · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/dev-cz-agents-ares
