Shrimp Task ManagerSAFE
Shrimp Task Manager is a task tool built for AI Agents, emphasizing chain-of-thought, reflection, and style consistency. It converts natural language into structured dev tasks with dependency tracking and iterative refinement, enabling agent-like developer behavior in reasoning AI systems.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
🇺🇸 English | 🇩🇪 Deutsch | 🇪🇸 Español | 🇫🇷 Français | 🇮🇹 Italiano | 🇮🇳 हिन्दी | 🇰🇷 한국어 | 🇧🇷 Português | 🇷🇺 Русский | 🇨🇳 中文
🦐 Intelligent task management for AI-powered development - Break down complex projects into manageable tasks, maintain context across sessions, and accelerate your development workflow.
[](https://www.youtube.com/watch?v=Arzu0lV09so)
[Watch Demo Video](https://www.youtube.com/watch?v=Arzu0lV09so) • Quick Start • Documentation
[](https://smithery.ai/server/@cjo4m06/mcp-shrimp-task-manager)
🚀 Quick Start
Prerequisites
- Node.js 18+
- npm or yarn
- MCP-compatible AI client (Claude Code, etc.)
Installation
Installing Claude Code
Windows 11 (with WSL2):
# First, ensure WSL2 is installed (in PowerShell as Administrator) wsl --install # Enter Ubuntu/WSL environment wsl -d Ubuntu # Install Claude Code globally npm install -g @anthropic-ai/claude-code # Start Claude Code claude
macOS/Linux:
# Install Claude Code globally npm install -g @anthropic-ai/claude-code # Start Claude Code claude
Installing Shrimp Task Manager
# Clone the repository git clone https://github.com/cjo4m06/mcp-shrimp-task-manager.git cd mcp-shrimp-task-manager # Install dependencies npm install # Build the project npm run build
Configure Claude Code
Create
16a6ae982b56OBSERVED · 2026-09-23Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add shrimp-task-viewer --env OPENAI_API_KEY=${OPENAI_API_KEY} --env OPEN_AI_KEY_SHRIMP_TASK_VIEWER=${OPEN_AI_KEY_SHRIMP_TASK_VIEWER} -- npx -y [email protected]{
"mcpServers": {
"shrimp-task-viewer": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"OPENAI_API_KEY": "${OPENAI_API_KEY}",
"OPEN_AI_KEY_SHRIMP_TASK_VIEWER": "${OPEN_AI_KEY_SHRIMP_TASK_VIEWER}"
}
}
}
}Exposed tools (2)
2 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Название | read | Описание |
任務2 | read | 任務2描述 |
Trust audit
SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (7 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (18)
tools/task-viewer/Screenshots
.shrimp-viewer.pid
import { Task } from "../../types/index.js";import { Task } from "../../types/index.js";import { Task, TaskStatus } from "../../types/index.js";import { Task } from "../../types/index.js";import { Task, TaskStatus } from "../../types/index.js";# Access at http://127.0.0.1:9998
Navigieren Sie zu `http://127.0.0.1:9998` (Produktion) oder `http://localhost:3000` (Entwicklung)
Naviguez vers `http://127.0.0.1:9998` (production) ou `http://localhost:3000` (développement)
`http://127.0.0.1:9998` (प्रोडक्शन) या `http://localhost:3000` (डेवलपमेंट) पर नेविगेट करें
Naviga a `http://127.0.0.1:9998` (produzione) o `http://localhost:3000` (sviluppo)
@modelcontextprotocol/sdk, dotenv, express, get-port, uuid, zod, zod-to-json-schema, @types/express
@headlessui/react, @tanstack/react-table, @types/react, @types/react-dom, @types/react-syntax-highlighter, @uiw/react-md-editor, @vitejs/plugin-react, busboy
3. The application will automatically load these environment variables when starting
# Add to ~/.zshrc
# Add to ~/.bashrc
curl -sSL https://raw.githubusercontent.com/cjo4m06/mcp-shrimp-task-manager/main/install.sh | bash
Gates applied: no_behavioural_pass.
16a6ae982b56full audit observations/trust-audit/mcp-server/cjo4m06__shrimp-task-manager.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-09-23 | 16a6ae982b56 | SAFE | B | 87 | source changed, verdict held |
Questions
What is the Shrimp Task Manager MCP server?
Shrimp Task Manager is a task tool built for AI Agents, emphasizing chain-of-thought, reflection, and style consistency. It converts natural language into structured dev tasks with dependency tracking and iterative refinement, enabling agent-like developer behavior in reasoning AI systems.
What tools does Shrimp Task Manager expose?
2 in total: 2 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Shrimp Task Manager safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Shrimp Task Manager need?
It reads OPENAI_API_KEY and OPEN_AI_KEY_SHRIMP_TASK_VIEWER from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Shrimp Task Manager run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as shrimp-task-viewer at 3.0.0.
How current is this page?
The grade is for one exact copy of the source (16a6ae982b56), read on 2026-09-23. The repository is watched and re-audited when it changes.