OmniFocus EnhancedSAFE
Enhanced Model Context Protocol (MCP) server for OmniFocus with complete subtask support, perspective views (Inbox/Flagged/Forecast/Tags), ultimate task filtering, and direct access to custom perspectives. Seamlessly integrate OmniFocus with Claude AI for intelligent task management.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/omnifocus-mcp-enhanced) [](https://opensource.org/licenses/MIT) [](https://nodejs.org/) [](https://www.apple.com/macos/)
🌟 NEW: Native Custom Perspective Access with Hierarchical Display!
Transform OmniFocus into an AI-powered productivity powerhouse with custom perspective support
Enhanced Model Context Protocol (MCP) server for OmniFocus featuring native custom perspective access, hierarchical task display, AI-optimized tool selection, and comprehensive task management.
In plain English: this lets your AI assistant read your OmniFocus data, create tasks/projects, organize subtasks, review perspectives, and help you plan work without you manually jumping between apps.
🌠 Why This Project Exists
OmniFocus is already powerful, but it is still mostly a tool you drive by hand.
The bigger idea behind this project is simple:
- less clicking, more conversation
- less manual cleanup, more AI-assisted planning
- less tool memorization, more natural task management
The goal is not just to expose more OmniFocus commands. The goal is to let you work with OmniFocus like this:
Plan my day. Clean up my Inbox. Turn these notes into a project. Show me what is blocked. Reorganize these tasks safely.
If that feels natural, this MCP server is doing its job.
Want to see where the project is heading next? See the [roadmap](https://github.com/jqlts1/omnifocus-mcp-enhanced/blob/main/docs/roadmap/2026-02
13eceb8f9a9dOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add omnifocus-mcp-enhanced -- npx -y [email protected]
{
"mcpServers": {
"omnifocus-mcp-enhanced": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (25)
10 read · 9 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_omnifocus_task | write | Add a new task to OmniFocus |
add_project | write | Add a new project to OmniFocus |
append_to_note | read | Append text to a task or project note without overwriting the existing note. Useful for logging progress or adding context. |
batch_add_items | write | Add multiple tasks or projects to OmniFocus in a single operation |
batch_complete_tasks | read | Mark tasks complete or incomplete by stable ID. Accepts up to 100 items with optional completion dates. Preflights every ID, verifies every result, and restores previous states on failure. Repeating tasks generate new instances when completed. |
batch_edit_items | write | Edit fields and tags on up to 100 tasks or projects by stable ID. Each item names one object with taskId or projectId and carries only the fields it changes; an omitted field is untouched and an explicit null clears it. Dates accept an absolute value or a signed shift such as \ |
batch_move_tasks | write | Move a confirmed set of tasks to projects, parent tasks, or Inbox. The complete batch is validated before any change and every destination is verified afterward. |
batch_remove_items | destructive | Remove a user-confirmed set of tasks or projects by stable ID. The complete batch is validated before deletion and every ID is verified absent afterward. |
count_tasks | read | Count tasks matching filters without returning the full list. Fast |
create_project_from_outline | write | Create one user-confirmed project tree with stable folder/tag IDs. The complete outline is preflighted, created in one OmniFocus request, and read back for verification. |
dump_database | read | Gets the current state of your OmniFocus database |
duplicate_task | read | Duplicate an existing task, optionally with its subtasks, and optionally with a new name. Useful for template-based workflows. |
edit_item | write | Edit a task or project in OmniFocus |
filter_tasks | read | Advanced task filtering by status, dates, projects, tags, search, and more, with optional subtask-tree expansion |
get_projects | read | List OmniFocus projects or projects due for review. Use view=all (default) for status/folder filters, or view=due_for_review for overdue review work. |
get_task_by_id | read | Get information about a specific task by ID or name |
get_tasks | read | Read tasks from inbox, flagged, forecast, tag, or custom perspective. Use source to select the view; source-specific parameters are strictly validated. |
manage_folders | destructive | List, get, add, edit, or remove OmniFocus folders. This mixed-operation tool is conservatively marked destructive: list/get are read-only, add/edit mutate, and remove permanently deletes contained projects and tasks. |
manage_tags | destructive | List, search, add, edit, or remove OmniFocus tags. This mixed-operation tool is conservatively marked destructive: list/search are read-only, add/edit mutate, and remove deletes the selected tag plus child tags but keeps tasks. |
manage_task_notifications | destructive | List, add, or remove task notifications. This mixed-operation tool is conservatively marked destructive: list is read-only, add mutates, and remove deletes one or all notifications. |
mark_projects_reviewed | write | Mark a user-confirmed set of active or on-hold projects reviewed. The complete batch is validated first and review dates are verified afterward. |
move_task | write | Move an existing task to a project, parent task, or inbox |
read_task_attachment | read | Read a task attachment reported by get_task_by_id. Images are returned as MCP image content when possible. |
remove_item | destructive | Remove a task or project from OmniFocus |
set_repetition_rule | destructive | Set, update, or clear the repeat rule on a task. Supports ICS rule strings, schedule type, anchor date, catch-up, end date, and repetition count. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (5 observation(s))
- Network
- declared (1 observation(s))
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (7)
batch_remove_items, manage_folders, manage_tags, manage_task_notifications, remove_item, set_repetition_rule
PACKAGE_VERSION="$(node -p "require('${SCRIPT_DIR}/../../package.json').version" 2>/dev/null || true)"return readFileSync(new URL(`../../${name}`, import.meta.url), 'utf8');import { executeAppleScript } from '../../utils/scriptExecution.js';import { buildAppleScriptJsonHelpers } from '../../utils/appleScriptJson.js';import { escapeAppleScriptString } from '../../utils/appleScriptString.js';@modelcontextprotocol/sdk, zod, @types/node, typescript
Gates applied: no_behavioural_pass.
13eceb8f9a9dfull audit observations/trust-audit/mcp-server/jqlts1__omnifocus-enhanced.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 13eceb8f9a9d | SAFE | B | 89 | first audit |
Questions
What is the OmniFocus Enhanced MCP server?
Enhanced Model Context Protocol (MCP) server for OmniFocus with complete subtask support, perspective views (Inbox/Flagged/Forecast/Tags), ultimate task filtering, and direct access to custom perspectives. Seamlessly integrate OmniFocus with Claude AI for intelligent task management.
What tools does OmniFocus Enhanced expose?
25 in total: 10 read-only, 9 that write, and 6 that can delete or overwrite (batch_remove_items, manage_folders, manage_tags, manage_task_notifications, remove_item). Every one is listed on this page with its risk.
Is OmniFocus Enhanced safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does OmniFocus Enhanced need?
No credential environment variables were found in its source, so it appears to need none.
How does OmniFocus Enhanced run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as omnifocus-mcp-enhanced at 2.4.0.
How current is this page?
The grade is for one exact copy of the source (13eceb8f9a9d), read on 2026-10-08. The repository is watched and re-audited when it changes.