Task OrchestratorBLOCK
Server-enforced workflow discipline for AI agents. An MCP server providing persistent work items, dependency graphs, quality gates, and actor attribution. Schemas define what agents must produce — the server blocks the call if they don't. Works with any MCP-compatible client.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Server-enforced workflow discipline for AI agents.
Prompt-based frameworks hope the LLM follows instructions. This one blocks the call if it doesn't.
[](https://github.com/jpicklyk/task-orchestrator/releases) [](https://github.com/jpicklyk/task-orchestrator/actions/workflows/test.yml) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.io)
Task Orchestrator is an MCP server that gives AI coding agents a persistent work item graph with quality gates enforced by the server, not the prompt. It is built for developers running multi-agent or multi-session coding workflows: an orchestrator dispatching sub-agents, a fresh session picking up yesterday's work, or an autonomous loop draining a backlog. It ships as a Docker image, works with any MCP client, and has an optional Claude Code plugin that adds skills and hooks on top.
New here? Start with the [illustrated field guide](https://jpicklyk.github.io/task-orchestrator/field-guide/). It explains the ideas on this page in short visual pages, several of them interactive: fire triggers at a phase gate, click a work breakdown through its dependencies, and watch a schema resolve.
The Problem
Multi-agent workflows need infrastructure the model doesn't provide. When an orchestrator dispatches sub-agents across sessions, there's no built-in way to enforce what documentation must exist before work starts, track which agent made which change, or guarantee dependency ordering across a work breakdown. These are structural concerns — they belong in the server, not in prompts.
Task Orchestrator puts them i
3c163c09ad68OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add task-orchestrator:3.16.0 -- docker run -i --rm ghcr.io/jpicklyk/task-orchestrator:3.16.0:None
Exposed tools (6)
6 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
audit | read | Barrier-per-phase audit: reviewers, gap critic, adversarial verify, synthesis report, and a triage-derived findings proposal. |
implement-wave | read | Schedules queue/work seats across a wave of MCP work items — milestones, per-file locks, entry mapping, and rerun-safe replay. |
retro-analysis | read | Two-phase retrospective trend matcher: shards trends, observations, and retrospectives across Match agents, then adjudicates ambiguous and orphan findings into matched trends or new-trend candidates. |
review-wave | read | Runs independent, lane-derived review agents across a wave of MCP work items already in the review phase — validates lane coverage, aggregates verdicts, and guards reviewer independence. |
to-band | read | Show or hide the Task Orchestrator in-flight band |
to-graph | read | Open the Task Orchestrator work graph (active feature, an item id, or root) |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
const builder = new Function(`${slice}\nreturn {${CORE_NAMES.join(',')}};`)gradle-wrapper.jar
const normalized = text.startsWith('') ? text.slice(1) : text;private const val TOKEN = "sse-root-scope-fail-closed-test-token-abc123"
private const val TOKEN = "sync-lost-sse-test-token-xyz789"
private const val TOKEN = "tag-scope-test-token-abc123"
val token = "integration-write-token-s8"
val token = "integration-write-token-s9a"
.nojekyll
const builder = new Function(`${slice}\nreturn {${names.join(',')}};`)const builder = new Function(`${slice}\nreturn {${CORE_EXPORT_NAMES.join(',')}};`)import type { GraphSnapshot } from '../../types'import type { GateInfo, GraphNode, GraphSnapshot } from '../../types'import type { GraphNode, GraphSnapshot } from '../../types'import type { GraphSnapshot, GraphStatus } from '../../types'export type { GateInfo, GraphEdge, GraphNode, GraphSnapshot, GraphStatus } from '../../types'val maliciousYaml = "!!java.net.URL [\"http://169.254.169.254/latest/meta-data/\"]"
for (const ok of ['http://localhost:3001', 'http://127.0.0.1:3001/', 'http://[::1]:3001', 'https://localhost']) expect(isLoopbackApiUrl(ok)).toBe(true)
() => fetchWithTimeout(`http://127.0.0.1:${port}/`, {}, 100),const res = await fetchWithTimeout(`http://127.0.0.1:${port}/`, {}, 2000);const res = await fetchWithTimeout(`http://127.0.0.1:${port}/`, {});await fetchWithTimeout(`http://127.0.0.1:${port}/`, { headers: { Authorization: 'Bearer tok-abc' } }, 2000);['I14', 'http://lоcalhost/'],
const home = homeWithClientJson('' + JSON.stringify({ apiUrl: 'http://bom:1' }));const home = homeWithClientJson('' + JSON.stringify({ apiUrl: ' http://bom:2/ ' }));Gates applied: no_behavioural_pass.
3c163c09ad68full audit observations/trust-audit/mcp-server/jpicklyk__task-orchestrator-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 3c163c09ad68 | BLOCK | F | 54 | first audit |
Questions
What is the Task Orchestrator MCP server?
Server-enforced workflow discipline for AI agents. An MCP server providing persistent work items, dependency graphs, quality gates, and actor attribution. Schemas define what agents must produce — the server blocks the call if they don't. Works with any MCP-compatible client.
What tools does Task Orchestrator expose?
6 in total: 6 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Task Orchestrator safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on.
What credentials does Task Orchestrator need?
It reads TASK_ORCHESTRATOR_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Task Orchestrator run?
It speaks stdio, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (3c163c09ad68), read on 2026-10-06. The repository is watched and re-audited when it changes.