Earlier quoted context omitted.
In this case, the creator has explained that this is all read only. So what’s the problem?
I don't see your point. If it's not a problem, can I have read-only access to your financials? Also, the article states that the initial implementation was using Chrome DevTools MCP. That doesn't sound like read-only to me.
Have you built a product like the OP and demonstrated that you've put a lot of time/thought/etc into the infrastructure? If not, then it's a clear no.
Also the credentials, etc are going to Plaid (and even with that, my few Plaid integrations have all been OAuth lately), not this company. This is exactly like Stripe. I'm not giving anything "sensitive" in terms of transactions to this company regarding bank details.