Atlas / MCP servers / jacepark12 / TickTick

TickTickSAFE

mcp/jacepark12/ticktick

MCP server that interacts with TickTick (Dida 365) via the TickTick Open API

Verdict
SAFE
Grade
B
Trust score
87 /100
Exposed tools
22 15r · 5w · 2d
Transport
stdio
License
—
Stars
298
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for TickTick that enables interacting with your TickTick task management system directly through Claude and other MCP clients.

Features

  • 📋 View all your TickTick projects and tasks
  • ✏️ Create new projects and tasks through natural language
  • 🔄 Update existing task details (title, content, dates, priority)
  • ✅ Mark tasks as complete
  • 🗑️ Delete tasks and projects
  • 🔄 Full integration with TickTick's open API
  • 🔌 Seamless integration with Claude and other MCP clients

Prerequisites

  • Python 3.10 or higher
  • uv - Fast Python package installer and resolver
  • TickTick account with API access
  • TickTick API credentials (Client ID, Client Secret, Access Token)

Installation

  1. Clone this repository:
git clone https://github.com/jacepark12/ticktick-mcp.git
cd ticktick-mcp
  1. Install with uv:
# Install uv if you don't have it already
curl -LsSf https://astral.sh/uv/install.sh | sh

# Create a virtual environment
uv venv

# Activate the virtual environment
# On macOS/Linux:
source .venv/bin/activate
# On Windows:
.venv\Scripts\activate

# Install the package
uv pip install -e .
  1. Authenticate with TickTick:
# Run the authentication flow
uv run -m ticktick_mcp.cli auth

This will:

  • Ask for your TickTick Client ID and Client Secret
  • Open a browser window for you to log in to TickTick
  • Automatically save your access tokens to a .env file
  1. Test your configuration:
uv run test_server.py

This will verify that your TickTick credentials are working correctly.

Authentication with TickTick

This server uses OAuth2 to authenticate with TickTick. The setup process is straightforward:

  1. Register your application at the [TickTick Developer Center](https://developer.ticktick.com/ma
Read from source at commit 1f25959deeccOBSERVED · 2026-10-05
02

Exposed tools (22)

15 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
batch_create_taskswrite
complete_taskread
create_projectwrite
create_subtaskwrite
create_taskwrite
delete_projectdestructive
delete_taskdestructive
get_all_tasksreadGet all tasks from TickTick. Ignores closed projects.
get_engaged_tasksread
get_next_tasksread
get_overdue_tasksreadGet all overdue tasks from TickTick. Ignores closed projects.
get_projectread
get_project_tasksread
get_projectsreadGet all projects from TickTick.
get_taskread
get_tasks_by_priorityread
get_tasks_due_in_daysread
get_tasks_due_this_weekreadGet all tasks from TickTick that are due within the next 7 days. Ignores closed projects.
get_tasks_due_todayreadGet all tasks from TickTick that are due today. Ignores closed projects.
get_tasks_due_tomorrowreadGet all tasks from TickTick that are due today. Ignores closed projects.
search_tasksread
update_taskwrite
03

Trust audit

SAFEgrade B · trust 87/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (9)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_project, delete_task
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.template
.env.template
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
requirements.txt
mcp, python-dotenv, requests
Why it matters. 3 requirement(s) not pinned with ==
Fix. pin exact versions
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:57
- Automatically save your access tokens to a `.env` file
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:84
The server handles token refresh automatically, so you won't need to reauthenticate unless you revoke access or delete your `.env` file.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
ticktick-openapi.md:12
In order to call TickTick's Open API, it is necessary to obtain an access token for the corresponding user. TickTick uses the OAuth2 protocol to obtain the access token.
Why it matters. asks the agent to read credentials
LOWSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
README.md:33
curl -LsSf https://astral.sh/uv/install.sh | sh
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
ticktick-openapi.md:41
To exchange the authorization code for an access token, make a POST request to `https://ticktick.com/oauth/token` with the following parameters(Content-Type: application/x-www-form-urlencoded):
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-05 · audit v0.4.1 · source sha 1f25959deeccfull audit observations/trust-audit/mcp-server/jacepark12__ticktick.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-051f25959deeccSAFEB87first audit
05

Questions

What is the TickTick MCP server?

MCP server that interacts with TickTick (Dida 365) via the TickTick Open API

What tools does TickTick expose?

22 in total: 15 read-only, 5 that write, and 2 that can delete or overwrite (delete_project, delete_task). Every one is listed on this page with its risk.

Is TickTick safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (87/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does TickTick need?

It reads TICKTICK_ACCESS_TOKEN, TICKTICK_AUTH_URL, TICKTICK_CLIENT_SECRET, TICKTICK_REFRESH_TOKEN and TICKTICK_TOKEN_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does TickTick run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (1f25959deecc), read on 2026-10-05. The repository is watched and re-audited when it changes.

Advertisement