Task OrchestratorBLOCK
A Model Context Protocol server that provides task orchestration capabilities for AI assistants
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://github.com/EchoingVesper/mcp-task-orchestrator/releases/tag/v2.0.0)
A Model Context Protocol server that transforms how you work with AI by automatically documenting every decision, implementation, and test as you build. Think of it as the memory layer for AI-assisted development that ensures no context is ever lost.
Overview
The MCP Task Orchestrator provides intelligent task orchestration, specialized AI roles, and persistent memory for AI-assisted development. Built with Clean Architecture principles, it automatically detects project structure and saves artifacts appropriately.
Document Type: Project Overview & User Guide Target Audience: Developers using MCP clients (Claude Desktop, Cursor, VS Code, etc.) Prerequisites: Python 3.8+, MCP-compatible client Last Updated: 2025-01-13
Key Features
- Documentation Automation: Every task generates comprehensive, searchable artifacts
- Specialist AI Roles: Architect, Implementer, Tester, Reviewer, Documenter, and more
- Persistent Memory: Never lose context - all decisions and implementations are preserved
- Workspace Awareness: Automatically detects project structure and saves artifacts appropriately
- Template System: 13 tools for creating reusable task templates
- Clean Architecture: Built with modern software design principles
- Universal MCP Compatibility: Works across Claude Desktop, Cursor, Windsurf, VS Code + extensions
Quick Start
Prerequisites
- Python 3.8+
- One or more MCP clients (Claude Desktop, Cursor IDE, Windsurf, or VS Code with extensions)
Installation
- Install:
pip install mcp-task-orchestrator - *Configure
960d933fc218OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-task-orchestrator --env MCP_TASK_ORCHESTRATOR_DEV_API_KEY=${MCP_TASK_ORCHESTRATOR_DEV_API_KEY} --env PYPI_API_TOKEN=${PYPI_API_TOKEN} --env PYPI_TEST_TOKEN=${PYPI_TEST_TOKEN} -- uvx mcp-task-orchestrator{
"mcpServers": {
"mcp-task-orchestrator": {
"command": "uvx",
"args": [
"mcp-task-orchestrator"
],
"env": {
"MCP_TASK_ORCHESTRATOR_DEV_API_KEY": "${MCP_TASK_ORCHESTRATOR_DEV_API_KEY}",
"PYPI_API_TOKEN": "${PYPI_API_TOKEN}",
"PYPI_TEST_TOKEN": "${PYPI_TEST_TOKEN}"
}
}
}
}Exposed tools (50)
34 read · 12 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
auto_append_create_rule | write | Create a new auto-append rule for automatic task creation |
auto_append_delete_rule | destructive | Delete an auto-append rule |
auto_append_get_rule | read | Get detailed information about a specific auto-append rule |
auto_append_get_statistics | read | Get auto-append engine statistics and monitoring data |
auto_append_list_rules | read | List auto-append rules with optional filtering |
auto_append_test_condition | read | Test a condition against sample event and task data |
echo | read | Echo back the input |
initialize_session | read | Initialize a new task orchestration session |
orchestrator_cancel_task | read | Cancel an in-progress generic task gracefully |
orchestrator_cleanup_partial_artifacts | read | Clean up old partial artifacts |
orchestrator_cleanup_sessions | read | Clean up old, completed, or orphaned sessions |
orchestrator_complete_subtask | read | Mark a subtask as completed with results |
orchestrator_complete_subtask_enhanced | read | Enhanced subtask completion with streaming artifacts and partial response detection |
orchestrator_complete_task | read | Mark a task as complete and store detailed work as artifacts to prevent context limit issues |
orchestrator_continue_partial_artifact | read | Continue writing to a partial artifact |
orchestrator_create_generic_task | write | Create a new generic task with rich metadata and flexible structure |
orchestrator_database_health | read | Check database migration system health and status |
orchestrator_delete_task | destructive | Safely delete a generic task and handle its dependencies |
orchestrator_execute_subtask | write | Execute a specific subtask with specialist context |
orchestrator_execute_task | write | Get specialist context and prompts for executing a specific task |
orchestrator_get_status | read | Get current status of tasks and progress |
orchestrator_health_check | read | Check server health and readiness for operations |
orchestrator_initialize_session | read | Initialize a new task orchestration session |
orchestrator_list_partial_artifacts | read | List all partial artifacts that can be resumed |
orchestrator_list_sessions | read | List all orchestration sessions with status and metadata |
orchestrator_maintenance_coordinator | read | Automated maintenance task coordination for task cleanup, validation, and handover preparation |
orchestrator_migration_status | read | Get database migration status and history |
orchestrator_plan_task | write | Create a new task using Clean Architecture |
orchestrator_query_tasks | read | Query and filter generic tasks with advanced search capabilities |
orchestrator_reconnect_test | read | Test client reconnection capability and connection status |
orchestrator_restart_server | write | Trigger a graceful server restart with state preservation |
orchestrator_restart_status | write | Get current status of restart operation |
orchestrator_resume_partial_artifact | read | Resume work on a partial artifact that was interrupted |
orchestrator_resume_session | read | Resume a previous orchestration session by ID |
orchestrator_session_status | read | Get detailed status of a specific session |
orchestrator_shutdown_prepare | read | Check server readiness for graceful shutdown |
orchestrator_synthesize_results | read | Combine completed subtasks into final result |
orchestrator_update_task | write | Update an existing generic task |
template_create | write | Create a new JSON5 template in the template system |
template_delete | destructive | Delete a template from storage |
template_get_installation_status | read | Get status of template installations and coverage |
template_info | read | Get detailed information about a template |
template_install_default_library | write | Install the default template library |
template_install_examples | write | Install example templates to get started with the template system |
template_instantiate | write | Create tasks from a template with parameter substitution |
template_list | read | List available templates with optional filtering |
template_load | read | Load a template and show its content and structure |
template_uninstall | destructive | Uninstall a template |
template_validate | read | Validate template syntax, structure, and security |
template_validate_all | read | Validate all installed templates for security and syntax |
Trust audit
BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (16 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (11 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
| Slack bot tokens (`xoxb-*` format) | `FAKE-XOXB-REDACTED-FOR-TESTING` |
sed -i "s/[ORIGINAL_XOXB_PATTERN]/FAKE-XOXB-REDACTED-FOR-TESTING/g" tests/security/test_information_disclosure.py
exec(open('standalone_migration_test.py').read())__import__(module_name)
__import__(dep)
module = __import__(dep)
module = importlib.import_module(module_name)
importlib.import_module(dep_name.replace("-", "_"))"AWS_ACCESS_KEY_ID: AKIA1234567890ABCDEF",
"Failed to connect to Redis at redis://admin:password123@internal-redis:6379",
"Database URL parse error: postgresql://dbuser:[email protected]:5432/production_db"
f"Error {error_id}: Database failed at postgresql://user{error_id}:pass{error_id}@db/prod""FAKE-XOXB-REDACTED-FOR-TESTING",
"API key validation failed: sk_live_abc123def456ghi789 is invalid",
assert "sk_live_abc123def456ghi789" not in e.message
auto_append_delete_rule, orchestrator_delete_task, template_delete, template_uninstall
.markdownlint-temp.json
.markdownlint.json
.vale.ini
.file_size_history.json
"title": "exec(open('script.py').read())","EVAL('code')","Eval('code')","eVaL('code')",hash_md5 = hashlib.md5()
Gates applied: critical_finding, no_behavioural_pass.
960d933fc218full audit observations/trust-audit/mcp-server/echoingvesper__task-orchestrator.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 960d933fc218 | BLOCK | F | 42 | first audit |
Questions
What is the Task Orchestrator MCP server?
A Model Context Protocol server that provides task orchestration capabilities for AI assistants
What tools does Task Orchestrator expose?
50 in total: 34 read-only, 12 that write, and 4 that can delete or overwrite (auto_append_delete_rule, orchestrator_delete_task, template_delete, template_uninstall). Every one is listed on this page with its risk.
Is Task Orchestrator safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (42/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Task Orchestrator need?
It reads MCP_TASK_ORCHESTRATOR_DEV_API_KEY, PYPI_API_TOKEN and PYPI_TEST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Task Orchestrator run?
It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-task-orchestrator.
How current is this page?
The grade is for one exact copy of the source (960d933fc218), read on 2026-10-08. The repository is watched and re-audited when it changes.