Atlas / MCP servers / agentrq / AgentRQ

AgentRQBLOCK

mcp/agentrq/agentrq-1

AgentRQ: Human-in-loop realtime conversational task manager for AI Agents. Self-hosted! Control your own agents from wherever you want Mobile, Web, Desktop. Designed to work well with your own Claude subscriptions and any harness with ACP support.

Verdict
BLOCK
Grade
F
Trust score
49 /100
Exposed tools
87 52r · 26w · 9d
Transport
streamable-http
License
Apache-2.0
Stars
1,132
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

简体中文

AgentRQ is a modern, high-performance platform designed for seamless collaboration between human operators and AI agents. It leverages the Model Context Protocol (MCP) to allow AI models (like Claude) to interact directly with your workspace's task management system.

🚀 Overview

Think of AgentRQ as a shared workspace where humans and AI agents work together seamlessly. You can break down complex goals into manageable tasks, and delegate work directly to your AI agents.

Because agents "see" the workspace state via MCP, they can autonomously pull their assigned tasks, update statuses, request permissions for sensitive actions, and communicate with you—all synchronized instantly across the platform in real-time.

✨ Features

Real captures from the running app — no mockups.

Visual Task Board

Every task Claude creates appears instantly on your board. See what it's working on, what it needs, and what it just finished — all from a clean, fast dashboard you can open on any device, as a list or a Kanban.

Task Scheduling

Give any task a launch date, or a recurring cadence — every 15 minutes, hourly, daily, weekly, custom days. A background poller ticks every minute and spawns the task the instant it's due, no server or agent needin

Read from source at commit 7f9062a4b703OBSERVED · 2026-09-25
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add dsh-plugin-agentrq --env AGENTRQ_ROOT_TOKEN=${AGENTRQ_ROOT_TOKEN} -- npx -y @agentrq/[email protected]
claude-desktop
{
  "mcpServers": {
    "dsh-plugin-agentrq": {
      "command": "npx",
      "args": [
        "-y",
        "@agentrq/[email protected]"
      ],
      "env": {
        "AGENTRQ_ROOT_TOKEN": "${AGENTRQ_ROOT_TOKEN}"
      }
    }
  }
}
03

Exposed tools (87)

52 read · 26 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AgentRQreadAI-powered task queue for autonomous agents
OpswriteRun things
alphareadnow described
approveMachineUpdatewriteInstall the agentrqd release a machine has offered. This stops every session on that machine and starts them again as new terminals: scrollback and in-flight work are lost.
archiveWorkspacereadArchive a workspace, hiding it from the default list without deleting anything.
compactreadShorten the context
createEnrolmentCodereadMint a single-use code for enrolling a new machine. It is shown once and is useless without access to the machine being enrolled.
createEventwriteCreate a named event that tasks can publish.
createEventTriggerwriteAdd a trigger, so publishing this event creates a task. In the body, {{EVENT_PAYLOAD}}
createTaskwriteCreate a task in a workspace. Assign it to an agent to have it worked on, or to a human
createWorkflowwriteCreate a workflow: a named chain in which one event\
createWorkflowStepwriteAdd a step: when the given event fires, create this task. Refused when it would
createWorkspacewriteCreate a workspace. The description is the mission agents are given.
deleteEventdestructivePermanently delete an event and its triggers.
deleteEventTriggerdestructiveRemove a trigger, so this event stops creating that task.
deleteMachinedestructiveRemove a machine. Its token stops working, so enrolling it again means running the enrolment command on the machine itself.
deleteTaskdestructivePermanently delete a task and its conversation. This cannot be undone.
deleteWorkflowdestructivePermanently delete a workflow and its steps.
deleteWorkflowStepdestructiveRemove one step from a workflow.
deleteWorkspacedestructivePermanently delete a workspace and everything in it. This cannot be undone — prefer
deleteWorkspaceSkilldestructiveDelete one of a workspace\
getAccountStatsreadActivity statistics across every workspace the user owns, over a time range, with a
getCurrentPagereadWhere the user is right now in the AgentRQ interface: the route path and its parameters.
getCurrentUserreadWho is signed in. Everything else these tools do is done as this user.
getEventreadOne event, with its payload guidelines.
getGlobalTaskStatsreadTask statistics across every workspace the user can see.
getMachinereadOne machine: its state, and its memory, CPU and disk.
getSessionreadOne agent session: which machine and workspace it belongs to, and whether it is still running.
getTaskreadOne task in full, including its conversation.
getTaskCountsreadHow many tasks a workspace has in each status.
getWorkflowreadOne workflow, with its layout and starting event.
getWorkflowTextreadA workflow as editable text — the whole thing in one document, which is usually easier
getWorkspacereadx
getWorkspaceMemoryreadOne of a workspace\
getWorkspaceSessionreadThe agent session running for a workspace, or null if none is. Answers
getWorkspaceSkillreadOne skill of a workspace, with the paths and sizes of its files but not their content.
getWorkspaceSkillFilewriteOne file of a skill, in full. Start with SKILL.md, which says which other files matter.
getWorkspaceStatsreadActivity statistics for a workspace over a time range.
getWorkspaceTokenreadThe workspace token an agent uses to connect to this workspace over MCP.
importWorkspaceSkillswriteImport skills from a public GitHub repository into a workspace, e.g. https://github.com/obra/superpowers
initwriteSet the project up
killSessionreadAsk a machine to end an agent session. Anything the agent has not saved is lost.
launchAgentwriteStart an agent for a workspace on a chosen machine. Answers before it has started: the session reports its own state.
listAcpAgentswriteThe acp-gateway agents a machine can run, for choosing an agent before launchAgent. Comes back empty
listAcpModelsreadThe models one acp-gateway agent supports, once an agent is chosen. Needs the workspace: the gateway has
listEventTasksreadTasks that were spawned by an event.
listEventTriggerswriteThe triggers on an event: what each publish creates, and where.
listEventswriteNamed signals that let a task in one workspace start tasks in another.
listMachineSessionswriteThe agent sessions that have run on a machine, newest first.
listMachinesreadComputers enrolled against this account that can host agents, with whether each is online and what it has left.
listTasksreadTasks in one workspace, or across every workspace when workspaceId is omitted.
listWorkflowStepsreadThe steps of a workflow: which event creates which task, where.
listWorkflowTasksreadTasks a workflow has created.
listWorkflowswriteWorkflows: chains of events and the tasks they create.
listWorkspaceMemoriesreadWhat the agents working in a workspace have written down for each other: name, size and when
listWorkspaceSkillSharesreadThe other workspaces one of a workspace\
listWorkspacesreadEvery workspace the signed-in user can see.
moveTaskwriteMove a task to a different workspace.
navigatereadOpen a page in the AgentRQ interface, moving the user there. Paths are the ones in the
removeWorkspaceSlackChannelreadDisconnect a workspace from its Slack channel.
renameMachinewriteRename a machine. The name is what the machines list and the launcher show.
replaceWorkflowFromTextreadReplace a workflow with the one described by this text. Everything not in the text is
replyToTaskwriteSend a message in a task conversation, as the signed-in user.
respondToElicitationreadAnswer a question an agent asked the user inside a task.
respondToTaskreadAnswer a task that is waiting on the user — accepting or rejecting what was proposed.
reviewreadUse when reviewing.
searchWorkspaceSkillsreadFind the skills a workspace\
sendPermissionVerdictwriteAnswer an agent asking permission to run something. This is the prompt the user sees in
setAgentConcurrencyreadAsk the workspace\
setAgentModelreadAsk the workspace\
setMachineEnableddestructiveTurn a machine on or off. Disabling is the kill switch: its connection is closed immediately and the next one is refused.
setWorkspaceSlackChannelreadConnect a workspace to a Slack channel so its activity is posted there.
shareWorkspaceSkillreadShare one of a workspace\
stopTaskwriteInterrupt a running task. Refuses when whatever is connected has no stop.
systematic-debuggingreadUse when debugging.
unarchiveWorkspacereadRestore an archived workspace to the default list.
unshareWorkspaceSkillwriteStop sharing a skill into a workspace; its agents can no longer load it.
updateEventreadChange an event\
updateEventTriggerwriteChange what a trigger creates.
updateScheduledTaskwriteChange the template of a recurring task — what each future run will be given.
updateTaskAllowAllCommandsreadTurn off (or back on) the per-command permission prompts for one task. Turning it on
updateTaskAssigneereadHand a task to the agent or back to a human.
updateTaskOrderreadReorder a task on the board.
updateTaskStatuswriteSet a task\
updateWorkflowreadChange a workflow. Only the fields given are altered.
updateWorkspacereadChange a workspace. Only the fields given are altered.
webreadSearch the web
04

Trust audit

BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (3 observation(s))
Network
declared (10 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHNetwork egress · net.env_exfil · CWE-200, CWE-319
desktop/scripts/verify-e2e.mjs:103
JSON.stringify(process.env ... fetch(
Why it matters. reads secrets in the same file that sends data out
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
daemon/cmd/agentrqd/main.go:34
agentrqd enroll --server <url> --code <code> [--profile <id>] [--insecure]
Why it matters. certificate verification is disabled
Fix. leave verification on
HIGHNetwork egress · net.tls_off · CWE-200, CWE-319
daemon/internal/config/server.go:73
"%w: %s. Use https, or pass --insecure to accept plain HTTP to this host",
Why it matters. certificate verification is disabled
Fix. leave verification on
MEDIUMInventory / provenance · inv.binary · CWE-1104
desktop/src/main/extensions/schedules.js
schedules.js
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
backend/internal/handler/coremcp/coremcp.go:46
if origin != "" && (strings.HasPrefix(origin, "http://localhost") || strings.HasPrefix(origin, "http://127.0.0.1") || strings.HasPrefix(origin, "https://localhost") || strings.HasPrefix(origin, "https
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
daemon/internal/supervisor/mcpconfig_test.go:105
const secret = "SUPERSECRETTOKENVALUE"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
daemon/wire/frame_test.go:268
const secret = "eyJhbGciOiJIUzI1NiJ9.SECRET.sig"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
desktop/test/extensions/storage.test.js:351
const { storage } = build({ initial: { secrets: { guardrail: { apiKey: 'from-another-machine' } } } })
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
backend/internal/controller/slack/slack_test.go:592
decToken := "xoxb-test-token"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
backend/internal/controller/slack/slack_test.go:650
decToken := "xoxb-test-token"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
backend/internal/controller/slack/slack_test.go:750
decToken := "xoxb-test-token"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
backend/internal/controller/slack/slack_test.go:867
decToken := "xoxb-test-token"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
backend/internal/controller/slack/slack_test.go:953
decToken := "xoxb-test-token"
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deleteEvent, deleteEventTrigger, deleteMachine, deleteTask, deleteWorkflow, deleteWorkflowStep, deleteWorkspace, deleteWorkspaceSkill, setMachineEnabled
Why it matters. 9 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
daemon/.goreleaser.yaml
.goreleaser.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
backend/internal/handler/api/openapi_test.go:29
const specPath = "../../../openapi.yaml"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
backend/internal/service/skillimport/skillimport_test.go:47
hdr.Linkname = "../../etc/passwd"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
backend/internal/service/skillimport/skillimport_test.go:159
{in: "https://github.com/obra/superpowers/tree/main/../../x", err: true},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
backend/internal/service/storage/storage_test.go:120
for _, id := range []string{"", "..", "../x", "a/../../x", "a//b", "/a", "a/"} {
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cli/agentrq-ws/test/attachments.test.js:137
assert.equal(resolveOutputPath('../../etc/passwd', undefined, { temp: '/tmp' }), '/tmp/passwd')
LOWNetwork egress · net.beacon_words · CWE-200, CWE-319
backend/internal/handler/mcp/oauth_client_binding_test.go:131
{"unknown scheme, exfiltration-looking host", "", "evil://x.example.com/steal", http.StatusBadRequest},
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
backend/internal/service/auth/cimd_test.go:69
{"169.254.169.254", true}, // link-local (cloud metadata endpoint)
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
backend/internal/service/auth/cimd_test.go:79
{"::ffff:169.254.169.254", true},
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
backend/internal/service/auth/cimd_test.go:83
{"64:ff9b::a9fe:a9fe", true}, // -> 169.254.169.254
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
backend/internal/service/auth/cimd_test.go:120
"https://169.254.169.254/latest",    // cloud metadata
Why it matters. cloud metadata endpoint: the classic SSRF credential grab

Gates applied: no_behavioural_pass.

Audited 2026-09-25 · audit v0.4.1 · source sha 7f9062a4b703full audit observations/trust-audit/mcp-server/agentrq__agentrq-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-09-257f9062a4b703BLOCKF49first audit
06

Questions

What is the AgentRQ MCP server?

AgentRQ: Human-in-loop realtime conversational task manager for AI Agents. Self-hosted! Control your own agents from wherever you want Mobile, Web, Desktop. Designed to work well with your own Claude subscriptions and any harness with ACP support.

What tools does AgentRQ expose?

87 in total: 52 read-only, 26 that write, and 9 that can delete or overwrite (deleteEvent, deleteEventTrigger, deleteMachine, deleteTask, deleteWorkflow). Every one is listed on this page with its risk.

Is AgentRQ safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (49/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does AgentRQ need?

It reads AGENTRQ_ROOT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does AgentRQ run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @agentrq/dsh-plugin-agentrq at 0.2.5.

How current is this page?

The grade is for one exact copy of the source (7f9062a4b703), read on 2026-09-25. The repository is watched and re-audited when it changes.

Advertisement