AgentRQBLOCK
AgentRQ: Human-in-loop realtime conversational task manager for AI Agents. Self-hosted! Control your own agents from wherever you want Mobile, Web, Desktop. Designed to work well with your own Claude subscriptions and any harness with ACP support.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
简体中文
AgentRQ is a modern, high-performance platform designed for seamless collaboration between human operators and AI agents. It leverages the Model Context Protocol (MCP) to allow AI models (like Claude) to interact directly with your workspace's task management system.
🚀 Overview
Think of AgentRQ as a shared workspace where humans and AI agents work together seamlessly. You can break down complex goals into manageable tasks, and delegate work directly to your AI agents.
Because agents "see" the workspace state via MCP, they can autonomously pull their assigned tasks, update statuses, request permissions for sensitive actions, and communicate with you—all synchronized instantly across the platform in real-time.
✨ Features
Real captures from the running app — no mockups.
Visual Task Board
Every task Claude creates appears instantly on your board. See what it's working on, what it needs, and what it just finished — all from a clean, fast dashboard you can open on any device, as a list or a Kanban.
Task Scheduling
Give any task a launch date, or a recurring cadence — every 15 minutes, hourly, daily, weekly, custom days. A background poller ticks every minute and spawns the task the instant it's due, no server or agent needin
7f9062a4b703OBSERVED · 2026-09-25Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add dsh-plugin-agentrq --env AGENTRQ_ROOT_TOKEN=${AGENTRQ_ROOT_TOKEN} -- npx -y @agentrq/[email protected]{
"mcpServers": {
"dsh-plugin-agentrq": {
"command": "npx",
"args": [
"-y",
"@agentrq/[email protected]"
],
"env": {
"AGENTRQ_ROOT_TOKEN": "${AGENTRQ_ROOT_TOKEN}"
}
}
}
}Exposed tools (87)
52 read · 26 write · 9 destructive. Blast radius: 9 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
AgentRQ | read | AI-powered task queue for autonomous agents |
Ops | write | Run things |
alpha | read | now described |
approveMachineUpdate | write | Install the agentrqd release a machine has offered. This stops every session on that machine and starts them again as new terminals: scrollback and in-flight work are lost. |
archiveWorkspace | read | Archive a workspace, hiding it from the default list without deleting anything. |
compact | read | Shorten the context |
createEnrolmentCode | read | Mint a single-use code for enrolling a new machine. It is shown once and is useless without access to the machine being enrolled. |
createEvent | write | Create a named event that tasks can publish. |
createEventTrigger | write | Add a trigger, so publishing this event creates a task. In the body, {{EVENT_PAYLOAD}} |
createTask | write | Create a task in a workspace. Assign it to an agent to have it worked on, or to a human |
createWorkflow | write | Create a workflow: a named chain in which one event\ |
createWorkflowStep | write | Add a step: when the given event fires, create this task. Refused when it would |
createWorkspace | write | Create a workspace. The description is the mission agents are given. |
deleteEvent | destructive | Permanently delete an event and its triggers. |
deleteEventTrigger | destructive | Remove a trigger, so this event stops creating that task. |
deleteMachine | destructive | Remove a machine. Its token stops working, so enrolling it again means running the enrolment command on the machine itself. |
deleteTask | destructive | Permanently delete a task and its conversation. This cannot be undone. |
deleteWorkflow | destructive | Permanently delete a workflow and its steps. |
deleteWorkflowStep | destructive | Remove one step from a workflow. |
deleteWorkspace | destructive | Permanently delete a workspace and everything in it. This cannot be undone — prefer |
deleteWorkspaceSkill | destructive | Delete one of a workspace\ |
getAccountStats | read | Activity statistics across every workspace the user owns, over a time range, with a |
getCurrentPage | read | Where the user is right now in the AgentRQ interface: the route path and its parameters. |
getCurrentUser | read | Who is signed in. Everything else these tools do is done as this user. |
getEvent | read | One event, with its payload guidelines. |
getGlobalTaskStats | read | Task statistics across every workspace the user can see. |
getMachine | read | One machine: its state, and its memory, CPU and disk. |
getSession | read | One agent session: which machine and workspace it belongs to, and whether it is still running. |
getTask | read | One task in full, including its conversation. |
getTaskCounts | read | How many tasks a workspace has in each status. |
getWorkflow | read | One workflow, with its layout and starting event. |
getWorkflowText | read | A workflow as editable text — the whole thing in one document, which is usually easier |
getWorkspace | read | x |
getWorkspaceMemory | read | One of a workspace\ |
getWorkspaceSession | read | The agent session running for a workspace, or null if none is. Answers |
getWorkspaceSkill | read | One skill of a workspace, with the paths and sizes of its files but not their content. |
getWorkspaceSkillFile | write | One file of a skill, in full. Start with SKILL.md, which says which other files matter. |
getWorkspaceStats | read | Activity statistics for a workspace over a time range. |
getWorkspaceToken | read | The workspace token an agent uses to connect to this workspace over MCP. |
importWorkspaceSkills | write | Import skills from a public GitHub repository into a workspace, e.g. https://github.com/obra/superpowers |
init | write | Set the project up |
killSession | read | Ask a machine to end an agent session. Anything the agent has not saved is lost. |
launchAgent | write | Start an agent for a workspace on a chosen machine. Answers before it has started: the session reports its own state. |
listAcpAgents | write | The acp-gateway agents a machine can run, for choosing an agent before launchAgent. Comes back empty |
listAcpModels | read | The models one acp-gateway agent supports, once an agent is chosen. Needs the workspace: the gateway has |
listEventTasks | read | Tasks that were spawned by an event. |
listEventTriggers | write | The triggers on an event: what each publish creates, and where. |
listEvents | write | Named signals that let a task in one workspace start tasks in another. |
listMachineSessions | write | The agent sessions that have run on a machine, newest first. |
listMachines | read | Computers enrolled against this account that can host agents, with whether each is online and what it has left. |
listTasks | read | Tasks in one workspace, or across every workspace when workspaceId is omitted. |
listWorkflowSteps | read | The steps of a workflow: which event creates which task, where. |
listWorkflowTasks | read | Tasks a workflow has created. |
listWorkflows | write | Workflows: chains of events and the tasks they create. |
listWorkspaceMemories | read | What the agents working in a workspace have written down for each other: name, size and when |
listWorkspaceSkillShares | read | The other workspaces one of a workspace\ |
listWorkspaces | read | Every workspace the signed-in user can see. |
moveTask | write | Move a task to a different workspace. |
navigate | read | Open a page in the AgentRQ interface, moving the user there. Paths are the ones in the |
removeWorkspaceSlackChannel | read | Disconnect a workspace from its Slack channel. |
renameMachine | write | Rename a machine. The name is what the machines list and the launcher show. |
replaceWorkflowFromText | read | Replace a workflow with the one described by this text. Everything not in the text is |
replyToTask | write | Send a message in a task conversation, as the signed-in user. |
respondToElicitation | read | Answer a question an agent asked the user inside a task. |
respondToTask | read | Answer a task that is waiting on the user — accepting or rejecting what was proposed. |
review | read | Use when reviewing. |
searchWorkspaceSkills | read | Find the skills a workspace\ |
sendPermissionVerdict | write | Answer an agent asking permission to run something. This is the prompt the user sees in |
setAgentConcurrency | read | Ask the workspace\ |
setAgentModel | read | Ask the workspace\ |
setMachineEnabled | destructive | Turn a machine on or off. Disabling is the kill switch: its connection is closed immediately and the next one is refused. |
setWorkspaceSlackChannel | read | Connect a workspace to a Slack channel so its activity is posted there. |
shareWorkspaceSkill | read | Share one of a workspace\ |
stopTask | write | Interrupt a running task. Refuses when whatever is connected has no stop. |
systematic-debugging | read | Use when debugging. |
unarchiveWorkspace | read | Restore an archived workspace to the default list. |
unshareWorkspaceSkill | write | Stop sharing a skill into a workspace; its agents can no longer load it. |
updateEvent | read | Change an event\ |
updateEventTrigger | write | Change what a trigger creates. |
updateScheduledTask | write | Change the template of a recurring task — what each future run will be given. |
updateTaskAllowAllCommands | read | Turn off (or back on) the per-command permission prompts for one task. Turning it on |
updateTaskAssignee | read | Hand a task to the agent or back to a human. |
updateTaskOrder | read | Reorder a task on the board. |
updateTaskStatus | write | Set a task\ |
updateWorkflow | read | Change a workflow. Only the fields given are altered. |
updateWorkspace | read | Change a workspace. Only the fields given are altered. |
web | read | Search the web |
Trust audit
BLOCKgrade F · trust 49/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
JSON.stringify(process.env ... fetch(
agentrqd enroll --server <url> --code <code> [--profile <id>] [--insecure]
"%w: %s. Use https, or pass --insecure to accept plain HTTP to this host",
schedules.js
if origin != "" && (strings.HasPrefix(origin, "http://localhost") || strings.HasPrefix(origin, "http://127.0.0.1") || strings.HasPrefix(origin, "https://localhost") || strings.HasPrefix(origin, "https
const secret = "SUPERSECRETTOKENVALUE"
const secret = "eyJhbGciOiJIUzI1NiJ9.SECRET.sig"
const { storage } = build({ initial: { secrets: { guardrail: { apiKey: 'from-another-machine' } } } })decToken := "xoxb-test-token"
decToken := "xoxb-test-token"
decToken := "xoxb-test-token"
decToken := "xoxb-test-token"
decToken := "xoxb-test-token"
deleteEvent, deleteEventTrigger, deleteMachine, deleteTask, deleteWorkflow, deleteWorkflowStep, deleteWorkspace, deleteWorkspaceSkill, setMachineEnabled
.goreleaser.yaml
const specPath = "../../../openapi.yaml"
hdr.Linkname = "../../etc/passwd"
{in: "https://github.com/obra/superpowers/tree/main/../../x", err: true},for _, id := range []string{"", "..", "../x", "a/../../x", "a//b", "/a", "a/"} {assert.equal(resolveOutputPath('../../etc/passwd', undefined, { temp: '/tmp' }), '/tmp/passwd'){"unknown scheme, exfiltration-looking host", "", "evil://x.example.com/steal", http.StatusBadRequest},{"169.254.169.254", true}, // link-local (cloud metadata endpoint){"::ffff:169.254.169.254", true},{"64:ff9b::a9fe:a9fe", true}, // -> 169.254.169.254"https://169.254.169.254/latest", // cloud metadata
Gates applied: no_behavioural_pass.
7f9062a4b703full audit observations/trust-audit/mcp-server/agentrq__agentrq-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-25 | 7f9062a4b703 | BLOCK | F | 49 | first audit |
Questions
What is the AgentRQ MCP server?
AgentRQ: Human-in-loop realtime conversational task manager for AI Agents. Self-hosted! Control your own agents from wherever you want Mobile, Web, Desktop. Designed to work well with your own Claude subscriptions and any harness with ACP support.
What tools does AgentRQ expose?
87 in total: 52 read-only, 26 that write, and 9 that can delete or overwrite (deleteEvent, deleteEventTrigger, deleteMachine, deleteTask, deleteWorkflow). Every one is listed on this page with its risk.
Is AgentRQ safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (49/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 9 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does AgentRQ need?
It reads AGENTRQ_ROOT_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does AgentRQ run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as @agentrq/dsh-plugin-agentrq at 0.2.5.
How current is this page?
The grade is for one exact copy of the source (7f9062a4b703), read on 2026-09-25. The repository is watched and re-audited when it changes.