Atlas / MCP servers / davebream / tila

tilaCAUTION

mcp/davebream/tila

Durable state and artifact storage for multi-machine agentic work. Content-addressed artifacts, schema-validated records, first-writer-wins coordination. Cloudflare-native or local.

Verdict
CAUTION
Grade
F
Trust score
45 /100
Exposed tools
107 82r · 19w · 6d
Transport
stdio
License
MIT
Stars
0
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Durable state and artifact storage for multi-machine agentic work.

Content-addressed artifacts outside your git repo. Schema-validated records. Coordination primitives that prevent races.

Deploy to your own Cloudflare account, or run locally with zero infrastructure.

Status: v0.3.0 — see the latest published release. APIs may change before v1.0. Upgrading from v0.2.x requires coordinated client/Worker updates; read the upgrade notes before deploying.

Direction: tila is evolving into one development-management product around this coordination core: an orchestrator with workers across Mac/Linux hosts, then native Mac/iPhone clients. Cloudflare will be the shared backend and project keys the supported auth path. These are planned changes; the current release still includes local persistence and GitHub auth. See the roadmap for the first milestone and runtime evaluation.

For: framework authors, AI autopilot builders, and small teams (3 to 6 engineers) whose agents need shared state across multiple machines.

Contents

  • Why tila exists
  • What it looks like
  • Self-hosted
  • When you need tila
  • Quick start
  • For AI coding agents
  • Monorepo packages
  • Related projects
  • Contributing
  • FAQ

🪨 Why tila exists

Agent-produced artifacts (plans, designs, analysis reports, build outputs) pile up fast. Commit them to your repo and they rot in context: coding agents waste tokens parsing stale intermediate files, and your git history fills with noise no human reviews. Gitignore them and they vanish on clone, can't be shared across machines, and agents lose access on context switch. A separate repo jus

Read from source at commit a3fcaa80f023OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add tila-mcp-server -- npx -y tila-mcp-server@None
03

Exposed tools (107)

82 read · 19 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
ackreadAcknowledge this participant
addwriteAdd a relationship between artifacts
add-entrywriteAdd an entry to an index
adminreadManage project admin roster
applywriteApply schema changes
archivereadArchive a record
artifactreadManage artifacts
artifact-refreadManage entity-artifact references
artifactswriteArtifact upload (no claim; sizes round-robin), metadata read-back, and a periodic kind-filtered list. The embedded tier writes text blobs via writeText.
authreadManage tila authentication (instances, tokens, status)
cancelreadCancel a pending gate
catreadRead artifact text to stdout
claimreadClaim a task
claims-contendedreadParticipants contend for one or more hot resources: acquire, hold, release. Reports conflicts, takeovers and fence monotonicity.
claims-uncontendedreadPer-participant resource: acquire (exclusive), renew x3, release. No contention; pure claim-path cost.
closereadClose a task
cold-startwritePOST /admin/restart to evict the DO, then time the first summary read (cold) and three more (warm after restart).
completereadGenerate bash, zsh, fish or powershell completion scripts
configreadView project configuration
configurereadConfigure a custom domain for the tila Worker
createwriteCreate a gate on a resource
deletedestructiveDelete a signal group (admin)
deploywriteDeploy Worker and UI to Cloudflare via wrangler. Exit codes: 0 success, 1 deploy failed.
destroydestructiveDestroy a tila project and its resources
diffreadPreview schema changes without applying
disconnectdestructiveRemove local credentials (keep project config)
doctorreadCheck project health
entityreadDeprecated alias for
exportwriteCreate a complete checksummed project backup
fenced-writesreadFenced task updates (owner-mode claims) with a thief forcing stale-fence retries, or CAS record writes between paired participants.
forgetreadAlias for
gatereadManage coordination gates
getreadDownload an artifact
grantreadGrant admin access to a GitHub user
grepreadSearch artifact content by exact substring or bounded regex. Prints key:line: text per matching line. col is a character offset (ASCII-accurate); not a raw-byte offset.
groupreadGroups
heartbeatwriteSend a participant heartbeat
historyreadList artifact revisions
importwriteRestore a complete project backup
inboxreadShow this participant
indexreadManage index artifacts
infrareadManage account-level tila infrastructure
initreadJoin an existing tila project
inspectreadShow effective identity, role, capabilities, and restrictions
instancesreadManage registered tila instances
instantiatewriteInstantiate a template to create entities
issuereadIssue a new API token
journalreadQuery the project journal
journal-replayreadWriters append journal rows via claim cycles while readers page the journal with replay cursors and acknowledge progress.
latestreadGet the latest artifact of a given kind for a resource
lifecyclereadConfigure and inspect coding-session lifecycle integration
linkreadRegister and trust a tila instance, storing a credential in the keychain
listreadList active project admins
list-entriesreadList entries in an index
mcpreadMCP server configuration
migratereadEagerly promote legacy .tila/.env / .tila/.session credentials into the ~/.tila store
newwriteCreate a new task
openreadOpen the tila dashboard in your browser
patchwritePatch a record (JSON Merge Patch)
presencereadManage agent presence
presence-signalsreadPresence heartbeat, then a participant-targeted signal to a random peer, then inbox read and acknowledgement of every pending bench signal.
projectreadManage tila projects
provisionreadProvision account-level infrastructure (D1, R2, Worker, GitHub App)
putwriteUpload an artifact
readyreadList tasks with no open blockers
recordreadManage typed records
recoverreadRegenerate the DPoP keypair and re-bind to a fresh session (use after a lost or corrupted private key)
registerreadRegister the configured GitHub repo in the project allowlist
reindexwriteTrigger a batched FTS reindex for artifacts, entities, or both
relreadManage artifact relationships
relationshipreadManage task relationships (alias: rel)
releasereadRelease a task claim
removedestructiveRemove a registered instance (removes registry entry and keychain secrets)
renewreadRenew a task claim
reposreadManage the GitHub repo allowlist
resetdestructiveReset all project data
resolvereadResolve a pending gate
restorereadAppend a revision from an existing artifact
reviewreadRecord an explicit artifact review (a hash does not establish trust)
reviewsreadRead artifact review history
revokedestructiveRevoke admin access from a GitHub user
rotatereadRotate a scoped credential without changing its principal
schemareadManage project schema
searchreadFull-text search across indexed artifacts
sendwriteSend a signal to typed recipients
service-accountreadManage project service identities and workload bindings
setwriteSet a config value (writes to .tila/config.toml)
shellreadSpawn a sub-shell pinned to an instance (per-shell isolation; use
showreadShow current schema
signalreadSignal parity trial
sprintreadA task with one subtask
statereadShow claim state
statusreadShow all registered instances, trust, expiry, and which resolves here
summaryreadShow project summary
switchreadSwitch the active tila instance (process-global; use
tailreadShow recent journal events
taskreadManage tasks
teardownreadTear down account-level tila infrastructure
templatereadManage entity templates
testreadtest
tokenreadEmit the resolved bearer token to stdout (credential-helper mode)
treereadShow task tree view
typesreadList record types
unarchivereadUnarchive a record
updatewriteUpdate a task field
work-unitreadDeprecated alias for
writewriteWrite text content as an artifact
04

Trust audit

CAUTIONgrade F · trust 45/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (7 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/auth-store/src/providers/github.test.ts:264
token: "ghu_test_access_token",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/cli/src/__tests__/lib/instance-context.test.ts:230
token: "auto-discovery-leg-tok",
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/integration-tests/runtime/artifacts.test.ts:19
const token = "runtime-artifact-token";
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/dev-seed-records.sh:5
TOKEN="tila_dev_token_localonly"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
scripts/dev-seed.sh:5
TOKEN="tila_dev_token_localonly"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/cli/src/__tests__/commands/doctor.test.ts:217
pem: "-----BEGIN RSA PRIVATE KEY-----\n...",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/cli/src/__tests__/commands/doctor.test.ts:323
pem: "-----BEGIN RSA PRIVATE KEY-----\n...",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/cli/src/__tests__/commands/doctor.test.ts:360
pem: "-----BEGIN RSA PRIVATE KEY-----\n...",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/cli/src/__tests__/commands/infra.test.ts:214
pem: "-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----",
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
packages/cli/src/__tests__/commands/infra.test.ts:675
pem: "-----BEGIN PRIVATE KEY-----\ntest\n-----END PRIVATE KEY-----",
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete, destroy, disconnect, remove, reset, revoke
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaks.toml
.gitleaks.toml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitleaksignore
.gitleaksignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.graphifyignore
.graphifyignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mcp.json.example
.mcp.json.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.mergify.yml
.mergify.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/backend-do/test/do-correlation.test.ts:22
exec(statement: string, ...bindings: unknown[]) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/backend-do/test/migration-rollback.test.ts:20
exec(statement: string, ..._bindings: unknown[]): SqlExecResult {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/backend-do/test/migration-rollback.test.ts:61
exec(statement: string, ...bindings: unknown[]): SqlExecResult {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/backend-do/test/migration-rollback.test.ts:144
exec(statement: string, ..._bindings: unknown[]): SqlExecResult {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
packages/backend-embedded/test/migrations.test.ts:47
exec(statement: string, ...bindings: unknown[]) {
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
experiments/gunshi-parity/citty.ts:5
} from "../../packages/cli/src/commands/signal";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
experiments/gunshi-parity/citty.ts:10
} from "../../packages/cli/src/lib/output";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
experiments/gunshi-parity/fixture.ts:4
} from "../../packages/cli/src/commands/signal";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
experiments/gunshi-parity/gunshi.ts:6
} from "../../packages/cli/src/commands/signal";

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha a3fcaa80f023full audit observations/trust-audit/mcp-server/davebream__tila.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08a3fcaa80f023CAUTIONF45first audit
06

Questions

What is the tila MCP server?

Durable state and artifact storage for multi-machine agentic work. Content-addressed artifacts, schema-validated records, first-writer-wins coordination. Cloudflare-native or local.

What tools does tila expose?

107 in total: 82 read-only, 19 that write, and 6 that can delete or overwrite (delete, destroy, disconnect, remove, reset). Every one is listed on this page with its risk.

Is tila safe to connect to an agent?

With care. The audit graded it F (45/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does tila need?

It reads ACTIONS_ID_TOKEN_REQUEST_TOKEN, ACTIONS_ID_TOKEN_REQUEST_URL, CLOUDFLARE_API_TOKEN, GH_TOKEN, GITHUB_TOKEN, INFRA_ADMIN_TOKEN, TILA_API_TOKEN, TILA_LIFECYCLE_KEY, TILA_READ_TOKEN and TILA_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does tila run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @tila/worker at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (a3fcaa80f023), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement