Atlas / MCP servers / echoingvesper / Task Orchestrator

Task OrchestratorBLOCK

mcp/echoingvesper/task-orchestrator

A Model Context Protocol server that provides task orchestration capabilities for AI assistants

Verdict
BLOCK
Grade
F
Trust score
42 /100
Exposed tools
50 34r · 12w · 4d
Transport
stdio
License
MIT
Stars
28
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/MIT) [](https://www.python.org/downloads/) [](https://github.com/EchoingVesper/mcp-task-orchestrator/releases/tag/v2.0.0)

A Model Context Protocol server that transforms how you work with AI by automatically documenting every decision, implementation, and test as you build. Think of it as the memory layer for AI-assisted development that ensures no context is ever lost.

Overview

The MCP Task Orchestrator provides intelligent task orchestration, specialized AI roles, and persistent memory for AI-assisted development. Built with Clean Architecture principles, it automatically detects project structure and saves artifacts appropriately.

Document Type: Project Overview & User Guide Target Audience: Developers using MCP clients (Claude Desktop, Cursor, VS Code, etc.) Prerequisites: Python 3.8+, MCP-compatible client Last Updated: 2025-01-13

Key Features

  • Documentation Automation: Every task generates comprehensive, searchable artifacts
  • Specialist AI Roles: Architect, Implementer, Tester, Reviewer, Documenter, and more
  • Persistent Memory: Never lose context - all decisions and implementations are preserved
  • Workspace Awareness: Automatically detects project structure and saves artifacts appropriately
  • Template System: 13 tools for creating reusable task templates
  • Clean Architecture: Built with modern software design principles
  • Universal MCP Compatibility: Works across Claude Desktop, Cursor, Windsurf, VS Code + extensions

Quick Start

Prerequisites

  • Python 3.8+
  • One or more MCP clients (Claude Desktop, Cursor IDE, Windsurf, or VS Code with extensions)

Installation

  1. Install: pip install mcp-task-orchestrator
  2. *Configure
Read from source at commit 960d933fc218OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-task-orchestrator --env MCP_TASK_ORCHESTRATOR_DEV_API_KEY=${MCP_TASK_ORCHESTRATOR_DEV_API_KEY} --env PYPI_API_TOKEN=${PYPI_API_TOKEN} --env PYPI_TEST_TOKEN=${PYPI_TEST_TOKEN} -- uvx mcp-task-orchestrator
claude-desktop
{
  "mcpServers": {
    "mcp-task-orchestrator": {
      "command": "uvx",
      "args": [
        "mcp-task-orchestrator"
      ],
      "env": {
        "MCP_TASK_ORCHESTRATOR_DEV_API_KEY": "${MCP_TASK_ORCHESTRATOR_DEV_API_KEY}",
        "PYPI_API_TOKEN": "${PYPI_API_TOKEN}",
        "PYPI_TEST_TOKEN": "${PYPI_TEST_TOKEN}"
      }
    }
  }
}
03

Exposed tools (50)

34 read · 12 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
auto_append_create_rulewriteCreate a new auto-append rule for automatic task creation
auto_append_delete_ruledestructiveDelete an auto-append rule
auto_append_get_rulereadGet detailed information about a specific auto-append rule
auto_append_get_statisticsreadGet auto-append engine statistics and monitoring data
auto_append_list_rulesreadList auto-append rules with optional filtering
auto_append_test_conditionreadTest a condition against sample event and task data
echoreadEcho back the input
initialize_sessionreadInitialize a new task orchestration session
orchestrator_cancel_taskreadCancel an in-progress generic task gracefully
orchestrator_cleanup_partial_artifactsreadClean up old partial artifacts
orchestrator_cleanup_sessionsreadClean up old, completed, or orphaned sessions
orchestrator_complete_subtaskreadMark a subtask as completed with results
orchestrator_complete_subtask_enhancedreadEnhanced subtask completion with streaming artifacts and partial response detection
orchestrator_complete_taskreadMark a task as complete and store detailed work as artifacts to prevent context limit issues
orchestrator_continue_partial_artifactreadContinue writing to a partial artifact
orchestrator_create_generic_taskwriteCreate a new generic task with rich metadata and flexible structure
orchestrator_database_healthreadCheck database migration system health and status
orchestrator_delete_taskdestructiveSafely delete a generic task and handle its dependencies
orchestrator_execute_subtaskwriteExecute a specific subtask with specialist context
orchestrator_execute_taskwriteGet specialist context and prompts for executing a specific task
orchestrator_get_statusreadGet current status of tasks and progress
orchestrator_health_checkreadCheck server health and readiness for operations
orchestrator_initialize_sessionreadInitialize a new task orchestration session
orchestrator_list_partial_artifactsreadList all partial artifacts that can be resumed
orchestrator_list_sessionsreadList all orchestration sessions with status and metadata
orchestrator_maintenance_coordinatorreadAutomated maintenance task coordination for task cleanup, validation, and handover preparation
orchestrator_migration_statusreadGet database migration status and history
orchestrator_plan_taskwriteCreate a new task using Clean Architecture
orchestrator_query_tasksreadQuery and filter generic tasks with advanced search capabilities
orchestrator_reconnect_testreadTest client reconnection capability and connection status
orchestrator_restart_serverwriteTrigger a graceful server restart with state preservation
orchestrator_restart_statuswriteGet current status of restart operation
orchestrator_resume_partial_artifactreadResume work on a partial artifact that was interrupted
orchestrator_resume_sessionreadResume a previous orchestration session by ID
orchestrator_session_statusreadGet detailed status of a specific session
orchestrator_shutdown_preparereadCheck server readiness for graceful shutdown
orchestrator_synthesize_resultsreadCombine completed subtasks into final result
orchestrator_update_taskwriteUpdate an existing generic task
template_createwriteCreate a new JSON5 template in the template system
template_deletedestructiveDelete a template from storage
template_get_installation_statusreadGet status of template installations and coverage
template_inforeadGet detailed information about a template
template_install_default_librarywriteInstall the default template library
template_install_exampleswriteInstall example templates to get started with the template system
template_instantiatewriteCreate tasks from a template with parameter substitution
template_listreadList available templates with optional filtering
template_loadreadLoad a template and show its content and structure
template_uninstalldestructiveUninstall a template
template_validatereadValidate template syntax, structure, and security
template_validate_allreadValidate all installed templates for security and syntax
04

Trust audit

BLOCKgrade F · trust 42/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (16 observation(s))
Network
declared (10 observation(s))
Shell
declared (11 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
.claude/commands/git-operations/secrets-scanner-fix.md:53
| Slack bot tokens (`xoxb-*` format) | `FAKE-XOXB-REDACTED-FOR-TESTING` |
CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
.claude/commands/git-operations/secrets-scanner-fix.md:128
sed -i "s/[ORIGINAL_XOXB_PATTERN]/FAKE-XOXB-REDACTED-FOR-TESTING/g" tests/security/test_information_disclosure.py
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/testing/execute_test_direct.py:10
exec(open('standalone_migration_test.py').read())
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
mcp_task_orchestrator/infrastructure/mcp/handlers/core_handlers.py:899
__import__(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
mcp_task_orchestrator/infrastructure/monitoring/diagnostics.py:344
__import__(dep)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
mcp_task_orchestrator/infrastructure/monitoring/diagnostics.py:351
module = __import__(dep)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
mcp_task_orchestrator/reboot/orchestrator.py:136
module = importlib.import_module(module_name)
MEDIUMCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
mcp_task_orchestrator_cli/cli.py:523
importlib.import_module(dep_name.replace("-", "_"))
MEDIUMHard-coded secrets · secret.aws · CWE-798, CWE-321
tests/security/test_information_disclosure.py:154
"AWS_ACCESS_KEY_ID: AKIA1234567890ABCDEF",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
PRPs/validation/security-validation.md:827
"Failed to connect to Redis at redis://admin:password123@internal-redis:6379",
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
PRPs/validation/security-validation.md:830
"Database URL parse error: postgresql://dbuser:[email protected]:5432/production_db"
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
tests/security/test_information_disclosure.py:658
f"Error {error_id}: Database failed at postgresql://user{error_id}:pass{error_id}@db/prod"
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
tests/security/test_information_disclosure.py:126
"FAKE-XOXB-REDACTED-FOR-TESTING",
MEDIUMHard-coded secrets · secret.stripe · CWE-798, CWE-321
PRPs/validation/security-validation.md:829
"API key validation failed: sk_live_abc123def456ghi789 is invalid",
MEDIUMHard-coded secrets · secret.stripe · CWE-798, CWE-321
PRPs/validation/security-validation.md:845
assert "sk_live_abc123def456ghi789" not in e.message
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
auto_append_delete_rule, orchestrator_delete_task, template_delete, template_uninstall
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint-temp.json
.markdownlint-temp.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.markdownlint.json
.markdownlint.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vale.ini
.vale.ini
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
scripts/validation/.file_size_history.json
.file_size_history.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/security/template_system/test_template_security.py:72
"title": "exec(open('script.py').read())",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/security/template_system/test_template_security.py:507
"EVAL('code')",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/security/template_system/test_template_security.py:508
"Eval('code')",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
tests/security/template_system/test_template_security.py:509
"eVaL('code')",
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
mcp_task_orchestrator/db/backup_manager.py:352
hash_md5 = hashlib.md5()

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 960d933fc218full audit observations/trust-audit/mcp-server/echoingvesper__task-orchestrator.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08960d933fc218BLOCKF42first audit
06

Questions

What is the Task Orchestrator MCP server?

A Model Context Protocol server that provides task orchestration capabilities for AI assistants

What tools does Task Orchestrator expose?

50 in total: 34 read-only, 12 that write, and 4 that can delete or overwrite (auto_append_delete_rule, orchestrator_delete_task, template_delete, template_uninstall). Every one is listed on this page with its risk.

Is Task Orchestrator safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (42/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Task Orchestrator need?

It reads MCP_TASK_ORCHESTRATOR_DEV_API_KEY, PYPI_API_TOKEN and PYPI_TEST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Task Orchestrator run?

It speaks stdio, so it runs as a local process your client starts. It is published on PyPI as mcp-task-orchestrator.

How current is this page?

The grade is for one exact copy of the source (960d933fc218), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement