Atlas / MCP servers / jqlts1 / OmniFocus Enhanced

OmniFocus EnhancedSAFE

mcp/jqlts1/omnifocus-enhanced

Enhanced Model Context Protocol (MCP) server for OmniFocus with complete subtask support, perspective views (Inbox/Flagged/Forecast/Tags), ultimate task filtering, and direct access to custom perspectives. Seamlessly integrate OmniFocus with Claude AI for intelligent task management.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
25 10r · 9w · 6d
Transport
stdio
License
MIT
Stars
63
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/omnifocus-mcp-enhanced) [](https://opensource.org/licenses/MIT) [](https://nodejs.org/) [](https://www.apple.com/macos/)

🌟 NEW: Native Custom Perspective Access with Hierarchical Display!
Transform OmniFocus into an AI-powered productivity powerhouse with custom perspective support

Enhanced Model Context Protocol (MCP) server for OmniFocus featuring native custom perspective access, hierarchical task display, AI-optimized tool selection, and comprehensive task management.

In plain English: this lets your AI assistant read your OmniFocus data, create tasks/projects, organize subtasks, review perspectives, and help you plan work without you manually jumping between apps.

🌠 Why This Project Exists

OmniFocus is already powerful, but it is still mostly a tool you drive by hand.

The bigger idea behind this project is simple:

  • less clicking, more conversation
  • less manual cleanup, more AI-assisted planning
  • less tool memorization, more natural task management

The goal is not just to expose more OmniFocus commands. The goal is to let you work with OmniFocus like this:

Plan my day.
Clean up my Inbox.
Turn these notes into a project.
Show me what is blocked.
Reorganize these tasks safely.

If that feels natural, this MCP server is doing its job.

Want to see where the project is heading next? See the [roadmap](https://github.com/jqlts1/omnifocus-mcp-enhanced/blob/main/docs/roadmap/2026-02

Read from source at commit 13eceb8f9a9dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add omnifocus-mcp-enhanced -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "omnifocus-mcp-enhanced": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (25)

10 read · 9 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_omnifocus_taskwriteAdd a new task to OmniFocus
add_projectwriteAdd a new project to OmniFocus
append_to_notereadAppend text to a task or project note without overwriting the existing note. Useful for logging progress or adding context.
batch_add_itemswriteAdd multiple tasks or projects to OmniFocus in a single operation
batch_complete_tasksreadMark tasks complete or incomplete by stable ID. Accepts up to 100 items with optional completion dates. Preflights every ID, verifies every result, and restores previous states on failure. Repeating tasks generate new instances when completed.
batch_edit_itemswriteEdit fields and tags on up to 100 tasks or projects by stable ID. Each item names one object with taskId or projectId and carries only the fields it changes; an omitted field is untouched and an explicit null clears it. Dates accept an absolute value or a signed shift such as \
batch_move_taskswriteMove a confirmed set of tasks to projects, parent tasks, or Inbox. The complete batch is validated before any change and every destination is verified afterward.
batch_remove_itemsdestructiveRemove a user-confirmed set of tasks or projects by stable ID. The complete batch is validated before deletion and every ID is verified absent afterward.
count_tasksreadCount tasks matching filters without returning the full list. Fast
create_project_from_outlinewriteCreate one user-confirmed project tree with stable folder/tag IDs. The complete outline is preflighted, created in one OmniFocus request, and read back for verification.
dump_databasereadGets the current state of your OmniFocus database
duplicate_taskreadDuplicate an existing task, optionally with its subtasks, and optionally with a new name. Useful for template-based workflows.
edit_itemwriteEdit a task or project in OmniFocus
filter_tasksreadAdvanced task filtering by status, dates, projects, tags, search, and more, with optional subtask-tree expansion
get_projectsreadList OmniFocus projects or projects due for review. Use view=all (default) for status/folder filters, or view=due_for_review for overdue review work.
get_task_by_idreadGet information about a specific task by ID or name
get_tasksreadRead tasks from inbox, flagged, forecast, tag, or custom perspective. Use source to select the view; source-specific parameters are strictly validated.
manage_foldersdestructiveList, get, add, edit, or remove OmniFocus folders. This mixed-operation tool is conservatively marked destructive: list/get are read-only, add/edit mutate, and remove permanently deletes contained projects and tasks.
manage_tagsdestructiveList, search, add, edit, or remove OmniFocus tags. This mixed-operation tool is conservatively marked destructive: list/search are read-only, add/edit mutate, and remove deletes the selected tag plus child tags but keeps tasks.
manage_task_notificationsdestructiveList, add, or remove task notifications. This mixed-operation tool is conservatively marked destructive: list is read-only, add mutates, and remove deletes one or all notifications.
mark_projects_reviewedwriteMark a user-confirmed set of active or on-hold projects reviewed. The complete batch is validated first and review dates are verified afterward.
move_taskwriteMove an existing task to a project, parent task, or inbox
read_task_attachmentreadRead a task attachment reported by get_task_by_id. Images are returned as MCP image content when possible.
remove_itemdestructiveRemove a task or project from OmniFocus
set_repetition_ruledestructiveSet, update, or clear the repeat rule on a task. Supports ICS rule strings, schedule type, anchor date, catch-up, end date, and repetition count.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (1 observation(s))
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
batch_remove_items, manage_folders, manage_tags, manage_task_notifications, remove_item, set_repetition_rule
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
skills/omnifocus-cli/install.sh:27
PACKAGE_VERSION="$(node -p "require('${SCRIPT_DIR}/../../package.json').version" 2>/dev/null || true)"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/documentedCounts.test.ts:56
return readFileSync(new URL(`../../${name}`, import.meta.url), 'utf8');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/primitives/addFolder.ts:1
import { executeAppleScript } from '../../utils/scriptExecution.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/primitives/addFolder.ts:2
import { buildAppleScriptJsonHelpers } from '../../utils/appleScriptJson.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/primitives/addFolder.ts:3
import { escapeAppleScriptString } from '../../utils/appleScriptString.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 13eceb8f9a9dfull audit observations/trust-audit/mcp-server/jqlts1__omnifocus-enhanced.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0813eceb8f9a9dSAFEB89first audit
06

Questions

What is the OmniFocus Enhanced MCP server?

Enhanced Model Context Protocol (MCP) server for OmniFocus with complete subtask support, perspective views (Inbox/Flagged/Forecast/Tags), ultimate task filtering, and direct access to custom perspectives. Seamlessly integrate OmniFocus with Claude AI for intelligent task management.

What tools does OmniFocus Enhanced expose?

25 in total: 10 read-only, 9 that write, and 6 that can delete or overwrite (batch_remove_items, manage_folders, manage_tags, manage_task_notifications, remove_item). Every one is listed on this page with its risk.

Is OmniFocus Enhanced safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OmniFocus Enhanced need?

No credential environment variables were found in its source, so it appears to need none.

How does OmniFocus Enhanced run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as omnifocus-mcp-enhanced at 2.4.0.

How current is this page?

The grade is for one exact copy of the source (13eceb8f9a9d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement