Atlas / MCP servers / andresharpe / Dotbot

DotbotBLOCK

mcp/andresharpe/dotbot-1

Structured, auditable AI-assisted development for teams. Zero-dependency MCP server, web dashboard, and multi-provider AI CLI support.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
5 5r · 0w · 0d
Transport
—
License
MIT
Stars
52
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Structured, auditable AI-assisted development for teams.

What is dotbot?

Most AI coding tools give you a result but no record of how you got there - no trail of decisions for teammates to follow, no way to continue work across sessions, and no framework for managing large projects.

dotbot wraps AI-assisted coding in a managed, transparent workflow where every step is tracked:

Multi-workflow platform

  • Workflow-driven pipelines - Define multi-step pipelines in workflow.json manifests with tasks, dependencies, form configuration, MCP servers, and environment requirements. A project can have multiple workflows installed simultaneously, each run, re-run, and stopped independently.
  • Typed task system - Tasks can be prompt (AI-executed), script (PowerShell, no LLM), mcp (tool call), task_gen (generates sub-tasks dynamically), or prompt_template (AI with a workflow-specific prompt). Script, MCP, and task_gen tasks bypass the provider session but still execute in the task worktree and complete through the normal task status transition, including verification hooks. This enables deterministic pipeline stages within AI-orchestrated workflows.
  • Enterprise registries - Teams publish workflows, stacks, tools, and skills in git-hosted or local registries. dotbot registry add links a registry (private or public); dotbot init -Workflow registry:name installs from it. Registries are validated against a registry.json manifest with version compatibility checks and auth-failure hints for GitHub, Azure DevOps, and GitLab.
  • Workflows and stacks - Workflows (e.g. start-from-jira) define operational pipelines - what dotbot does. Stacks (e.g. dotnet, dotnet-blazor) add tech-specific skills, hooks, and MCP tools - what tech the project uses. Stacks compose additively with extends chains. Settings deep-merge across default -> workflows -> stacks.

Execution engine

  • **Sin
Read from source at commit 8e9438edcf68OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add dotbot-ui-e2e -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "dotbot-ui-e2e": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (5)

5 read · 0 write · 0 destructive.

ToolRiskDescription
Lread~2 weeks
Mread~1 week
Sread2-3 days
XLread3+ weeks
XSread~1 day
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHFilesystem / path · fs.credential_store · CWE-22, CWE-59
src/cli/registry-add.ps1:113
Write-Status "GitLab:     Add SSH key or set a PAT in ~/.netrc"
Why it matters. touches a credential store
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/server-dotnet/src/Dotbot.Server/Validation/QuestionTemplateValidator.cs:169
// IPv4 link-local (169.254/16) — includes AWS/Azure metadata 169.254.169.254. Not a legitimate review target.
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/runtime/Modules/Dotbot.Runtime/Private/Lifecycle.psm1:83
$http.Prefixes.Add("http://127.0.0.1:$p/")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/runtime/Modules/Dotbot.Runtime/Private/Lifecycle.psm1:117
$http.Prefixes.Add("http://127.0.0.1:$p/")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/runtime/Modules/Dotbot.Runtime/Private/Lifecycle.psm1:267
$url       = "http://127.0.0.1:$Port/"
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/server-dotnet/scripts/Seed-AzuriteContainers.ps1:65
$AzuriteDefaultBlobEndpoint = 'http://127.0.0.1:10000/devstoreaccount1'
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/server-dotnet/docs/SLACK-SETUP.md:287
$token = "xoxb-YOUR-TOKEN-HERE"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/server-dotnet/docs/TEAMS-SETUP.md:68
api_key         = "change-me-strong-random-secret"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
src/server-dotnet/docs/SLACK-SETUP.md:111
"BotToken": "xoxb-YOUR-TOKEN-HERE"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
src/server-dotnet/docs/SLACK-SETUP.md:287
$token = "xoxb-YOUR-TOKEN-HERE"
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
src/server-dotnet/terraform/.terraform.lock.hcl
.terraform.lock.hcl
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/cli/doctor.ps1:156
$themeDefault = Join-Path $PSScriptRoot "../../content/settings/theme.default.json"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/mcp/tools/steering-heartbeat/script.ps1:4
Import-Module (Join-Path $PSScriptRoot "../../../runtime/Modules/Dotbot.Core/Dotbot.Core.psm1")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/runtime/Scripts/Invoke-DotbotProcess.ps1:157
$mcpToolsDir = Join-Path $PSScriptRoot "../../mcp/tools"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/Test-Components.ps1:5812
@{ folder = '../../etc'; events = @('created') }
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/Test-StudioAPI.ps1:108
@{ Name = '../../etc';          Label = 'traversal (../../etc)' },
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/server-dotnet/tests/Dotbot.Server.Tests/Integration/PostTemplatesTests.cs:270
[InlineData("https://169.254.169.254/metadata")] // link-local / IMDS
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/server-dotnet/tests/Dotbot.Server.Tests/Unit/QuestionTemplateValidatorTests.cs:396
// Link-local — includes AWS/Azure IMDS at 169.254.169.254, also IPv6 fe80::/10
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/server-dotnet/tests/Dotbot.Server.Tests/Unit/QuestionTemplateValidatorTests.cs:397
[InlineData("https://169.254.169.254/metadata")]
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/server-dotnet/tests/Dotbot.Server.Tests/Unit/QuestionTemplateValidatorTests.cs:398
[InlineData("https://[::ffff:169.254.169.254]/metadata")]
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/server-dotnet/README.md:133
`UseDevelopmentStorage=true` is the standard Azurite shortcut understood by both the .NET `BlobServiceClient` and `az storage`. Avoid the long `DefaultEndpointsProtocol=http;...;BlobEndpoint=http://12
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
src/studio-ui/package.json
@dagrejs/dagre, @xyflow/react, react, react-dom, @types/react, @types/react-dom, @vitejs/plugin-react, concurrently
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
tests/e2e-server/package.json
@playwright/test, typescript
Why it matters. 2 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 8e9438edcf68full audit observations/trust-audit/mcp-server/andresharpe__dotbot-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-088e9438edcf68BLOCKD69first audit
06

Questions

What is the Dotbot MCP server?

Structured, auditable AI-assisted development for teams. Zero-dependency MCP server, web dashboard, and multi-provider AI CLI support.

What tools does Dotbot expose?

5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Dotbot safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 2 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Dotbot need?

No credential environment variables were found in its source, so it appears to need none.

How current is this page?

The grade is for one exact copy of the source (8e9438edcf68), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement