Atlas / MCP servers / jpicklyk / Task Orchestrator

Task OrchestratorBLOCK

mcp/jpicklyk/task-orchestrator-2

Server-enforced workflow discipline for AI agents. An MCP server providing persistent work items, dependency graphs, quality gates, and actor attribution. Schemas define what agents must produce — the server blocks the call if they don't. Works with any MCP-compatible client.

Verdict
BLOCK
Grade
F
Trust score
54 /100
Exposed tools
6 6r · 0w · 0d
Transport
stdio
License
MIT
Stars
207
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Server-enforced workflow discipline for AI agents.

Prompt-based frameworks hope the LLM follows instructions. This one blocks the call if it doesn't.

[](https://github.com/jpicklyk/task-orchestrator/releases) [](https://github.com/jpicklyk/task-orchestrator/actions/workflows/test.yml) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io)

Task Orchestrator is an MCP server that gives AI coding agents a persistent work item graph with quality gates enforced by the server, not the prompt. It is built for developers running multi-agent or multi-session coding workflows: an orchestrator dispatching sub-agents, a fresh session picking up yesterday's work, or an autonomous loop draining a backlog. It ships as a Docker image, works with any MCP client, and has an optional Claude Code plugin that adds skills and hooks on top.

New here? Start with the [illustrated field guide](https://jpicklyk.github.io/task-orchestrator/field-guide/). It explains the ideas on this page in short visual pages, several of them interactive: fire triggers at a phase gate, click a work breakdown through its dependencies, and watch a schema resolve.

The Problem

Multi-agent workflows need infrastructure the model doesn't provide. When an orchestrator dispatches sub-agents across sessions, there's no built-in way to enforce what documentation must exist before work starts, track which agent made which change, or guarantee dependency ordering across a work breakdown. These are structural concerns — they belong in the server, not in prompts.

Task Orchestrator puts them i

Read from source at commit 3c163c09ad68OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add task-orchestrator:3.16.0 -- docker run -i --rm ghcr.io/jpicklyk/task-orchestrator:3.16.0:None
03

Exposed tools (6)

6 read · 0 write · 0 destructive.

ToolRiskDescription
auditreadBarrier-per-phase audit: reviewers, gap critic, adversarial verify, synthesis report, and a triage-derived findings proposal.
implement-wavereadSchedules queue/work seats across a wave of MCP work items — milestones, per-file locks, entry mapping, and rerun-safe replay.
retro-analysisreadTwo-phase retrospective trend matcher: shards trends, observations, and retrospectives across Match agents, then adjudicates ambiguous and orphan findings into matched trends or new-trend candidates.
review-wavereadRuns independent, lane-derived review agents across a wave of MCP work items already in the review phase — validates lane coverage, aggregates verdicts, and guards reviewer independence.
to-bandreadShow or hide the Task Orchestrator in-flight band
to-graphreadOpen the Task Orchestrator work graph (active feature, an item id, or root)
04

Trust audit

BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (2 observation(s))
Shell
declared (1 observation(s))
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
claude-plugins/task-orchestrator/scripts/lib/wave-core.mjs:55
const builder = new Function(`${slice}\nreturn {${CORE_NAMES.join(',')}};`)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInventory / provenance · inv.binary · CWE-1104
gradle/wrapper/gradle-wrapper.jar
gradle-wrapper.jar
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
claude-plugins/task-orchestrator/hooks/config-sync.mjs:114
const normalized = text.startsWith('') ? text.slice(1) : text;
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
current/src/test/kotlin/io/github/jpicklyk/mcptask/current/interfaces/api/v1/events/SseRootScopeFailClosedTest.kt:82
private const val TOKEN = "sse-root-scope-fail-closed-test-token-abc123"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
current/src/test/kotlin/io/github/jpicklyk/mcptask/current/interfaces/api/v1/events/SyncLostSseDeliveryTest.kt:68
private const val TOKEN = "sync-lost-sse-test-token-xyz789"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
current/src/test/kotlin/io/github/jpicklyk/mcptask/current/interfaces/api/v1/events/TagScopeSseEventsTest.kt:70
private const val TOKEN = "tag-scope-test-token-abc123"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
current/src/test/kotlin/io/github/jpicklyk/mcptask/current/interfaces/api/v1/routes/RootPlacementScopeTest.kt:374
val token = "integration-write-token-s8"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
current/src/test/kotlin/io/github/jpicklyk/mcptask/current/interfaces/api/v1/routes/RootPlacementScopeTest.kt:406
val token = "integration-write-token-s9a"
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.nojekyll
.nojekyll
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
claude-plugins/task-orchestrator/scripts/tests/workflow-harness-ext.mjs:29
const builder = new Function(`${slice}\nreturn {${names.join(',')}};`)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
claude-plugins/task-orchestrator/scripts/tests/workflow-harness.mjs:58
const builder = new Function(`${slice}\nreturn {${CORE_EXPORT_NAMES.join(',')}};`)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
claude-plugins/task-orchestrator-mod/src/band/index.ts:11
import type { GraphSnapshot } from '../../types'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
claude-plugins/task-orchestrator-mod/src/band/model.ts:3
import type { GateInfo, GraphNode, GraphSnapshot } from '../../types'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
claude-plugins/task-orchestrator-mod/src/graph-data/events.ts:4
import type { GraphNode, GraphSnapshot } from '../../types'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
claude-plugins/task-orchestrator-mod/src/graph-data/index.ts:13
import type { GraphSnapshot, GraphStatus } from '../../types'
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
claude-plugins/task-orchestrator-mod/src/graph-data/index.ts:22
export type { GateInfo, GraphEdge, GraphNode, GraphSnapshot, GraphStatus } from '../../types'
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
current/src/test/kotlin/io/github/jpicklyk/mcptask/current/application/tools/config/ManageProjectConfigToolTest.kt:241
val maliciousYaml = "!!java.net.URL [\"http://169.254.169.254/latest/meta-data/\"]"
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
claude-plugins/task-orchestrator-mod/tests/graph-data.test.ts:847
for (const ok of ['http://localhost:3001', 'http://127.0.0.1:3001/', 'http://[::1]:3001', 'https://localhost']) expect(isLoopbackApiUrl(ok)).toBe(true)
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
claude-plugins/task-orchestrator/hooks/tests/api-client.test.mjs:330
() => fetchWithTimeout(`http://127.0.0.1:${port}/`, {}, 100),
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
claude-plugins/task-orchestrator/hooks/tests/api-client.test.mjs:348
const res = await fetchWithTimeout(`http://127.0.0.1:${port}/`, {}, 2000);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
claude-plugins/task-orchestrator/hooks/tests/api-client.test.mjs:363
const res = await fetchWithTimeout(`http://127.0.0.1:${port}/`, {});
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
claude-plugins/task-orchestrator/hooks/tests/api-client.test.mjs:379
await fetchWithTimeout(`http://127.0.0.1:${port}/`, { headers: { Authorization: 'Bearer tok-abc' } }, 2000);
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
claude-plugins/task-orchestrator/hooks/tests/api-client.test.mjs:572
['I14', 'http://lоcalhost/'],
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
claude-plugins/task-orchestrator/hooks/tests/api-client.test.mjs:232
const home = homeWithClientJson('' + JSON.stringify({ apiUrl: 'http://bom:1' }));
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
claude-plugins/task-orchestrator/hooks/tests/api-client.test.mjs:262
const home = homeWithClientJson('' + JSON.stringify({ apiUrl: ' http://bom:2/ ' }));

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 3c163c09ad68full audit observations/trust-audit/mcp-server/jpicklyk__task-orchestrator-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-063c163c09ad68BLOCKF54first audit
06

Questions

What is the Task Orchestrator MCP server?

Server-enforced workflow discipline for AI agents. An MCP server providing persistent work items, dependency graphs, quality gates, and actor attribution. Schemas define what agents must produce — the server blocks the call if they don't. Works with any MCP-compatible client.

What tools does Task Orchestrator expose?

6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Task Orchestrator safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (54/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.

What credentials does Task Orchestrator need?

It reads TASK_ORCHESTRATOR_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Task Orchestrator run?

It speaks stdio, so it runs as a local process your client starts.

How current is this page?

The grade is for one exact copy of the source (3c163c09ad68), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement