Atlas / MCP servers / 7836246 / Claude Team

Claude TeamSAFE

mcp/7836246/claude-team

🤖 Multi-Agent MCP Server - Let Claude Code / Windsurf / Cursor orchestrate GPT, Claude, Gemini to work as an AI dev team

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
25 23r · 2w · 0d
Transport
stdio
License
MIT
Stars
49
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Multi-Agent MCP Server for AI-Powered Development Teams

Orchestrate GPT, Claude, Gemini and more to collaborate on complex tasks

[](https://www.npmjs.com/package/claude-team) [](https://www.npmjs.com/package/claude-team) [](https://nodejs.org/) [](https://modelcontextprotocol.io) [](LICENSE) [](https://github.com/7836246/claude-team-mcp)

English | 简体中文

✨ Features

🚀 Quick Start

Installation

# Global install
npm install -g claude-team

# Or use directly with npx (no install needed)
npx claude-team

Basic Configuration

Add to your IDE's MCP configuration file:

📍 Configuration File

Read from source at commit 443bd1d6391eOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add claude-team --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env CLAUDE_TEAM_API_KEY=${CLAUDE_TEAM_API_KEY} --env CLAUDE_TEAM_MAIN_KEY=${CLAUDE_TEAM_MAIN_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "claude-team": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "CLAUDE_TEAM_API_KEY": "${CLAUDE_TEAM_API_KEY}",
        "CLAUDE_TEAM_MAIN_KEY": "${CLAUDE_TEAM_MAIN_KEY}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (25)

23 read · 2 write · 0 destructive.

ToolRiskDescription
analyze_project_structureread分析项目结构,识别技术栈和架构
ask_expertread向特定专家咨询问题
code_reviewread让专家审查代码
cost_estimateread预估任务执行成本(Token 用量、预计耗时)
explain_planread解释 Tech Lead 会如何分配任务(不实际执行)
fix_bugread让 QA 专家修复 Bug
generate_commit_messagewrite根据代码变更生成 Git commit message
history_contextread获取最近的协作上下文,可用于继续之前的工作
history_getread获取某次协作的详细记录
history_listread查看团队协作历史记录列表
history_searchread搜索协作历史记录
list_workflowsread列出所有可用的工作流模板
read_project_filesread读取项目文件内容,让专家了解代码上下文
run_workflowwrite使用指定工作流执行任务
suggest_workflowread根据任务自动推荐合适的工作流
team_dashboardread查看团队当前状态:可用专家、模型配置、最近活动
team_workread让 AI 开发团队协作完成任务。团队包含前端专家、后端专家、QA专家,会智能分配任务并互相协作。
usage_statsread查看各模型的使用统计(调用次数、成功率、平均耗时)
代码审查工作流read多维度代码审查流程
代码生成工作流read用于从需求生成代码的标准流程
代码重构工作流read用于代码重构的标准流程
我的工作流read自定义工作流
文档生成工作流read自动生成技术文档
自定义read自定义工作流
自定义代码生成read自定义的代码生成流程
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (2)

LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/collaboration/cache.ts:54
return createHash('md5').update(normalized).digest('hex');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @google/generative-ai, @modelcontextprotocol/sdk, openai, p-limit, yaml, zod, @eslint/js
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 443bd1d6391efull audit observations/trust-audit/mcp-server/7836246__claude-team.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08443bd1d6391eSAFEB89first audit
06

Questions

What is the Claude Team MCP server?

🤖 Multi-Agent MCP Server - Let Claude Code / Windsurf / Cursor orchestrate GPT, Claude, Gemini to work as an AI dev team

What tools does Claude Team expose?

25 in total: 23 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Claude Team safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Claude Team need?

It reads ANTHROPIC_API_KEY, CLAUDE_TEAM_API_KEY, CLAUDE_TEAM_MAIN_KEY, GEMINI_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Claude Team run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as claude-team at 0.4.1.

How current is this page?

The grade is for one exact copy of the source (443bd1d6391e), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement