Atlas / MCP servers / hridaya423 / Conductor Tasks

Conductor TasksCAUTION

mcp/hridaya423/conductor-tasks

A task management system designed for AI development

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
26 20r · 5w · 1d
Transport
stdio
License
MIT
Stars
74
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://opensource.org/licenses/MIT) [](https://badge.fury.io/js/conductor-tasks)

Transform requirements into actionable tasks, generate implementation plans, track progress, and accelerate development – all powered by AI, directly within your workflow.

Conductor Tasks is an intelligent assistant designed for developers. It integrates seamlessly into your editor (via MCP) or works as a standalone CLI tool, leveraging multiple LLMs to streamline your development process from planning to execution.

Key Features

  • AI-Powered Task Generation: Instantly parse Product Requirements Documents (PRDs), markdown files, or even unstructured notes into structured, actionable tasks.
  • Intelligent Task Expansion & Planning: Automatically break down complex tasks into detailed subtasks and generate step-by-step implementation plans using context-aware AI.
  • Powerful CLI for Automation: Leverage a comprehensive command-line interface for scripting, automation, and use outside of an editor.
  • Versatile Task Templating: Create new tasks from predefined or custom templates, standardizing common workflows and saving setup time.
  • Visual Task Management: Get a clear overview of your project with Kanban boards, dependency trees, and summary dashboards
  • Multi-Provider LLM Flexibility: Works out-of-the-box with OpenAI, Anthropic, Groq, Mistral, Google Gemini, Perplexity, xAI, Azure OpenAI. Easily configure custom/local OpenAI-compatible endpoints (like Ollama or LM Studio). You're not locked into a single provider – choose the best LLM for each specific need.

Why Conductor Tasks?

While many AI-powered task management tools offer valuable assistance, Conductor Tasks is engineered to pro

Read from source at commit 96df0096e974OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add conductor-tasks --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env CLAUDE_API_KEY=${CLAUDE_API_KEY} --env GEMINI_API_KEY=${GEMINI_API_KEY} --env GROQ_API_KEY=${GROQ_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "conductor-tasks": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "CLAUDE_API_KEY": "${CLAUDE_API_KEY}",
        "GEMINI_API_KEY": "${GEMINI_API_KEY}",
        "GROQ_API_KEY": "${GROQ_API_KEY}"
      }
    }
  }
}
03

Exposed tools (26)

20 read · 5 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
.roomodereadRoo Code Mode Configuration
.windsurfrulesreadWindsurf IDE Rules
add-task-notewriteAdd a note, progress update, or comment to a task
conductor-tasks.rulesreadCline IDE Rule: conductor-tasks.rules
create-taskwriteCreate a new task with details
create-task-from-templatewriteCreate a new task from a template
delete-taskdestructiveDelete a task
expand-taskreadExpand a task with more detailed information and subtasks
generate-diffreadGenerate a diff for a file based on a change description.
generate-implementation-stepsreadGenerate detailed implementation steps for a task
get-next-taskreadGet the next task to work on
get-taskreadGet details of a specific task
get-task-templatereadGet details of a specific task template
help-implement-taskreadGet AI assistance to implement a specific task
initialize-projectreadInitialize the project, including task management (TASKS.md) and IDE rules.
list-task-templatesreadList available task templates
list-tasksreadGet a list of tasks with filtering and sorting options
parse-prdwriteParse a PRD (Product Requirements Document) and create tasks from it
parse-prd-filereadParse a PRD file from disk and extract tasks
propose-diffreadPropose a diff to be applied to a file. Currently acknowledges only; does not apply.
research-topicreadResearch a topic using available LLM capabilities (e.g., Perplexity, tool-calling for search).
suggest-task-improvementsreadGet AI suggestions for improving a task
update-taskwriteUpdate an existing task
visualize-tasks-dashboardreadDisplay task dashboard with summary statistics
visualize-tasks-dependency-treereadDisplay task dependency tree
visualize-tasks-kanbanreadDisplay tasks in a Kanban board view
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
build/core/ruleGenerator.js:1173
│   └── [!!] #126 Create user profile page 👨💻
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
build/core/ruleGenerator.js:1179
Status: ✅ Done  🕒 Todo  👨💻 In Progress  👀 Review  ⛔ Blocked
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete-task
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
build/llm/providers/anthropic.js:3
import { ErrorHandler, ErrorCategory, ErrorSeverity, TaskError } from '../../core/errorHandler.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
build/llm/providers/anthropic.js:4
import { JsonUtils } from '../../core/jsonUtils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
build/llm/providers/gemini.d.ts:1
import { LLMProvider, LLMProviderConfig, LLMRequest, LLMResponse } from '../../core/types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
build/llm/providers/gemini.js:3
import { JsonUtils } from '../../core/jsonUtils.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
build/llm/providers/gemini.js:4
import { ErrorHandler, ErrorCategory, ErrorSeverity, TaskError } from '../../core/errorHandler.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@anthropic-ai/sdk, @google/generative-ai, @mistralai/mistralai, @modelcontextprotocol/sdk, ajv, chalk, commander, diff
Why it matters. 26 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 96df0096e974full audit observations/trust-audit/mcp-server/hridaya423__conductor-tasks.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0796df0096e974CAUTIONB89first audit
06

Questions

What is the Conductor Tasks MCP server?

A task management system designed for AI development

What tools does Conductor Tasks expose?

26 in total: 20 read-only, 5 that write, and 1 that can delete or overwrite (delete-task). Every one is listed on this page with its risk.

Is Conductor Tasks safe to connect to an agent?

With care. The audit graded it B (89/100) and found 9 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Conductor Tasks need?

It reads ANTHROPIC_API_KEY, CLAUDE_API_KEY, GEMINI_API_KEY, GROQ_API_KEY, MAX_TOKENS, MISTRAL_API_KEY, MIXTRAL_API_KEY, OLLAMA_API_KEY, OPENAI_API_KEY, OPENROUTER_API_KEY, PERPLEXITY_API_KEY and XAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Conductor Tasks run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as conductor-tasks at 0.2.4.

How current is this page?

The grade is for one exact copy of the source (96df0096e974), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement