Atlas / MCP servers / andyeverything / OpenProject

OpenProjectSAFE

mcp/andyeverything/openproject

A Model Context Protocol (MCP) server that provides seamless integration with OpenProject API v3.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
46 25r · 14w · 7d
Transport
sse · stdio
License
—
Stars
88
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/andyeverything-openproject-mcp-server)

⚠️ This is an early-stage project. Do not use it productively – contributions welcome!

A Model Context Protocol (MCP) server that provides seamless integration with OpenProject API v3. This server enables LLM applications to interact with OpenProject for project management, work package tracking, and task creation.

Features

  • 🔌 Full OpenProject API v3 Integration
  • 📋 Project Management: List and filter projects
  • 📝 Work Package Management: Create, list, and filter work packages
  • 🏷️ Type Management: List available work package types
  • 🔐 Secure Authentication: API key-based authentication
  • 🌐 Proxy Support: Optional HTTP proxy configuration
  • 🚀 Async Operations: Built with modern async/await patterns
  • 📊 Comprehensive Logging: Configurable logging levels

Prerequisites

  • Python 3.10 or higher
  • uv (fast Python package manager)
  • An OpenProject instance (cloud or self-hosted)
  • OpenProject API key (generated from your user profile)

Installation

1. Install uv (if not already installed)

macOS/Linux:

curl -LsSf https://astral.sh/uv/install.sh | sh

Windows:

powershell -c "irm https://astral.sh/uv/install.ps1 | iex"

Alternative (using pip):

pip install uv

2. Clone and Setup the Project

git clone https://github.com/yourusername/openproject-mcp.git
cd openproject-mcp

3. Create Virtual Environment and Install Dependencies

# Create virtual environment and install dependencies in one command
uv sync

Alternative (manual steps):

# C
Read from source at commit 3b42657d35dbOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add openproject-mcp-server --env MCP_API_KEYS=${MCP_API_KEYS} --env OPENPROJECT_API_KEY=${OPENPROJECT_API_KEY} -- uvx openproject-mcp-server
claude-desktop
{
  "mcpServers": {
    "openproject-mcp-server": {
      "command": "uvx",
      "args": [
        "openproject-mcp-server"
      ],
      "env": {
        "MCP_API_KEYS": "${MCP_API_KEYS}",
        "OPENPROJECT_API_KEY": "${OPENPROJECT_API_KEY}"
      }
    }
  }
}
03

Exposed tools (46)

25 read · 14 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
check_permissionsreadCheck current user permissions and capabilities
create_membershipwriteCreate a new project membership
create_newswriteCreate a new news entry for a project.
create_projectwriteCreate a new project
create_time_entrywriteCreate a new time entry
create_versionwriteCreate a new project version/milestone
create_work_packagewriteCreate a new work package with optional date fields
create_work_package_relationwriteCreate a relationship between work packages
delete_membershipdestructiveDelete a membership
delete_newsdestructiveDelete a news entry permanently.
delete_projectdestructiveDelete a project
delete_time_entrydestructiveDelete a time entry
delete_work_packagedestructiveDelete a work package
delete_work_package_relationdestructiveDelete a work package relation
get_membershipreadGet detailed information about a specific membership
get_newsreadGet detailed information about a specific news entry.
get_projectreadGet detailed information about a specific project
get_rolereadGet detailed information about a specific role
get_userreadGet detailed information about a specific user
get_work_packagereadGet detailed information about a specific work package
get_work_package_relationreadGet detailed information about a specific work package relation
list_membershipsreadList project memberships
list_newsreadList news entries with filtering and pagination.
list_prioritiesreadList available work package priorities
list_project_membersreadList all members of a specific project
list_projectsreadList all OpenProject projects
list_rolesreadList all available roles
list_statusesreadList available work package statuses
list_time_entriesreadList time entries
list_time_entry_activitiesreadList available time entry activities
list_typesreadList available work package types
list_user_projectsreadList all projects a specific user is assigned to
list_usersreadList all users
list_versionsreadList project versions/milestones
list_work_package_childrenreadList all child work packages of a parent
list_work_package_relationsreadList work package relations with optional filtering
list_work_packagesreadList work packages with optional pagination
remove_work_package_parentdestructiveRemove parent relationship from a work package (make it top-level)
set_work_package_parentwriteSet a parent for a work package (create parent-child relationship)
test_connectionreadTest the connection to the OpenProject API
update_membershipwriteUpdate an existing membership
update_newswriteUpdate an existing news entry.
update_projectwriteUpdate an existing project
update_time_entrywriteUpdate an existing time entry
update_work_packagewriteUpdate an existing work package including dates
update_work_package_relationwriteUpdate an existing work package relation
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_membership, delete_news, delete_project, delete_time_entry, delete_work_package, delete_work_package_relation, remove_work_package_parent
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.binary · CWE-1104
docs/Agile_Scrum_Weekly_Report_Template.docx
Agile_Scrum_Weekly_Report_Template.docx
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
LOWInventory / provenance · inv.hidden_file · CWE-1104
.fastmcp.yaml
.fastmcp.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, aiohttp, python-dotenv, certifi
Why it matters. 4 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
.claude/agents/api-documenter.md:7
You are a senior API documenter with expertise in creating world-class API documentation. Your focus spans OpenAPI specification writing, interactive documentation portals, code example generation, an
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
HUONG_DAN_QUAN_TRI_VIEN.md:94
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:33
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 3b42657d35dbfull audit observations/trust-audit/mcp-server/andyeverything__openproject.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-073b42657d35dbSAFEB89first audit
06

Questions

What is the OpenProject MCP server?

A Model Context Protocol (MCP) server that provides seamless integration with OpenProject API v3.

What tools does OpenProject expose?

46 in total: 25 read-only, 14 that write, and 7 that can delete or overwrite (delete_membership, delete_news, delete_project, delete_time_entry, delete_work_package). Every one is listed on this page with its risk.

Is OpenProject safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OpenProject need?

It reads MCP_API_KEYS and OPENPROJECT_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OpenProject run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on PyPI as openproject-mcp-server.

How current is this page?

The grade is for one exact copy of the source (3b42657d35db), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement