Atlas / MCP servers / ivelin-web / Tempo

TempoBLOCK

mcp/ivelin-web/tempo

MCP server for managing Tempo worklogs in Jira

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
7 7r · 0w · 0d
Transport
stdio
License
MIT
Stars
46
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/ivelin-web-tempo-mcp-server)

A Model Context Protocol (MCP) server for managing Tempo worklogs in Jira. This server provides tools for tracking time and managing worklogs through Tempo's API, making it accessible through Claude, Cursor and other MCP-compatible clients.

[](https://www.npmjs.com/package/@ivelin-web/tempo-mcp-server) [](https://opensource.org/licenses/MIT)

Features

  • Retrieve Worklogs: Get all worklogs for a specific date range
  • Create Worklog: Log time against Jira issues
  • Bulk Create: Create multiple worklogs in a single operation
  • Edit Worklog: Modify time spent, dates, and descriptions
  • Delete Worklog: Remove existing worklogs
  • Missing Days Report: Find working days where you logged less than expected (uses Tempo's user-schedule, so holidays and non-working days are skipped automatically)
  • Worklog Analytics: Aggregate hours by issue, account, day, week, or month with totals and percentages

System Requirements

  • Node.js 18+ (LTS recommended) — only needed for the local stdio modes
  • Jira Cloud instance
  • Tempo API token
  • Jira API token (not required when using OAuth 2.0 PKCE authentication)

Usage Options

There are three ways to use this MCP server:

  1. Remote / Cloudflare Workers (no install) — host once, share with your team. Each user generates their own URL via a setup page and pastes it into Claude.ai or ChatGPT. Works from web and mobile.
  2. NPX: Run directly with npx on your laptop, no clone required.
  3. Local Clone: Clone the repository for development or customization.

If you just want to use the server, option 1 is the easiest and works on phones too. If you're a maintainer deploying for your t

Read from source at commit 92a2db59a58aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add tempo-mcp-server -- npx -y @ivelin-web/[email protected]
claude-desktop
{
  "mcpServers": {
    "tempo-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@ivelin-web/[email protected]"
      ]
    }
  }
}
03

Exposed tools (7)

7 read · 0 write · 0 destructive.

ToolRiskDescription
bulkCreateWorklogsread
createWorklogread
deleteWorklogread
editWorklogread
getMissingWorklogDaysread
getWorklogAnalyticsread
retrieveWorklogsread
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/oauth.ts:254
exec(cmd);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWInventory / provenance · inv.hidden_file · CWE-1104
.dev.vars.example
.dev.vars.example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWObfuscation / stealth · obf.base64_blob · CWE-506, CWE-94
README.md:181
[![Install MCP Server](https://cursor.com/deeplink/mcp-install-dark.svg)](https://cursor.com/install-mcp?name=Jira%20Tempo&config=eyJjb21tYW5kIjoibnB4IC15IEBpdmVsaW4td2ViL3RlbXBvLW1jcC1zZXJ2ZXIiLCJlbn
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
src/remote/storage.ts:64
const s = atob(b64);
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, zod, @cloudflare/workers-types, agents, @eslint/js, @types/node, eslint
Why it matters. 16 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 92a2db59a58afull audit observations/trust-audit/mcp-server/ivelin-web__tempo.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0892a2db59a58aBLOCKD69first audit
06

Questions

What is the Tempo MCP server?

MCP server for managing Tempo worklogs in Jira

What tools does Tempo expose?

7 in total: 7 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Tempo safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Tempo need?

No credential environment variables were found in its source, so it appears to need none.

How does Tempo run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @ivelin-web/tempo-mcp-server at 1.8.0.

How current is this page?

The grade is for one exact copy of the source (92a2db59a58a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement