Atlas / MCP servers / bradrisse / Kanban

KanbanCAUTION

mcp/bradrisse/kanban

MCP Kanban is a specialized middleware designed to facilitate interaction between Large Language Models (LLMs) and Planka, a Kanban board application. It serves as an intermediary layer that provides LLMs with a simplified and enhanced API to interact with Planka's task management system.

Verdict
CAUTION
Grade
B
Trust score
82 /100
Exposed tools
8 8r · 0w · 0d
Transport
stdio
License
—
Stars
60
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Welcome to the Kanban MCP project! 🎉 This project integrates Planka kanban boards with Cursor's Machine Control Protocol (MCP) to enable AI assistants like Claude to manage your kanban boards.

🤔 What is Kanban MCP?

Kanban MCP is a bridge between Planka (an open-source kanban board) and Cursor's Machine Control Protocol. It allows AI assistants like Claude to:

  • 📋 View and manage projects, boards, lists, and cards
  • ✅ Create and update tasks
  • 💬 Add comments to cards
  • 🔄 Move cards between lists
  • ⏱️ Track time spent on tasks
  • 🚀 And much more!

This integration enables a seamless workflow where you can ask Claude to help manage your development tasks, track progress, and organize your work.

🚦 Quick Start

📋 Prerequisites

  • 🐳 Docker for running Planka
  • 🔄 Git for cloning the repository
  • 🟢 Node.js (version 18 or above) and npm for development

📥 Installation

  1. Clone this repository:
git clone https://github.com/bradrisse/kanban-mcp.git
cd kanban-mcp
  1. Install dependencies and build the TypeScript code:
npm install
npm run build
  1. Start the Planka containers:
npm run up
  1. Access the Planka Kanban board:
  2. Default URL: http://localhost:3333
  3. Default credentials:
  4. Email: [email protected]
  5. Password: demo
  1. Configure Cursor to use the MCP server:
  2. In Cursor, go to Settings > Features > MCP
  3. Add a new MCP server with the following configuration:
{
"mcpServers": {
"kanban": {
"command": "node",
"args": ["/path/to/kanban-mcp/dist/index.js"],
"env": {
"PLANKA_BASE_URL": "http://localhost:3333",
"PLANKA_AGENT_EMAIL": "[email protected]",
"PLANKA_AGENT_PASSWORD": "demo"
}
}
}
}
  • Replace /path/to/kanban-mcp with the act
Read from source at commit a3dab10ca221OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-kanban --env PLANKA_AGENT_PASSWORD=${PLANKA_AGENT_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-kanban": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "PLANKA_AGENT_PASSWORD": "${PLANKA_AGENT_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (8)

8 read · 0 write · 0 destructive.

ToolRiskDescription
mcp_kanban_card_managerreadManage kanban cards with various operations
mcp_kanban_comment_managerreadManage card comments with various operations
mcp_kanban_label_managerreadManage kanban labels with various operations
mcp_kanban_list_managerreadManage kanban lists with various operations
mcp_kanban_membership_managerreadManage board memberships with various operations
mcp_kanban_project_board_managerreadManage projects and boards with various operations
mcp_kanban_stopwatchreadManage card stopwatches for time tracking
mcp_kanban_task_managerreadManage kanban tasks with various operations
04

Trust audit

CAUTIONgrade B · trust 82/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryFAIL
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (4)

HIGHHard-coded secrets · inv.env_committed · CWE-798, CWE-321
.env
.env
Why it matters. a real .env in the package
Fix. ship .env.example with placeholders only
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env
.env
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/node, @types/node-fetch, node-fetch, universal-user-agent, zod, zod-to-json-schema, @jest/globals, @types/jest
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha a3dab10ca221full audit observations/trust-audit/mcp-server/bradrisse__kanban.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08a3dab10ca221CAUTIONB82first audit
06

Questions

What is the Kanban MCP server?

MCP Kanban is a specialized middleware designed to facilitate interaction between Large Language Models (LLMs) and Planka, a Kanban board application. It serves as an intermediary layer that provides LLMs with a simplified and enhanced API to interact with Planka's task management system.

What tools does Kanban expose?

8 in total: 8 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Kanban safe to connect to an agent?

With care. The audit graded it B (82/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Kanban need?

It reads PLANKA_AGENT_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Kanban run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-kanban at 0.0.6.

How current is this page?

The grade is for one exact copy of the source (a3dab10ca221), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement