Spec WorkflowBLOCK
Intelligent spec workflow management MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/spec-workflow-mcp) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.com)
English | 简体中文
Guide AI to systematically complete software development through a structured Requirements → Design → Tasks workflow, ensuring code implementation stays aligned with business needs.
Why Use It?
❌ Without Spec Workflow
- AI jumps randomly between tasks, lacking systematic approach
- Requirements disconnect from actual code implementation
- Scattered documentation, difficult to track project progress
- Missing design decision records
✅ With Spec Workflow
- AI completes tasks sequentially, maintaining focus and context
- Complete traceability from user stories to code implementation
- Standardized document templates with automatic progress management
- Each stage requires confirmation, ensuring correct direction
- Persistent progress: Continue from where you left off with
check, even in new conversations
Recent Updates
v1.0.7 - 🎯 Improved reliability for most models to manage tasks with spec workflow v1.0.6 - ✨ Batch task completion: Complete multiple tasks at once for faster progress on large projects v1.0.5 - 🐛 Edge case fixes: Distinguish between "task not found" and "task already completed" to prevent workflow interruption v1.0.4 - ✅ Task management: Added task completion tracking for systematic project progression v1.0.3 - 🎉 Initial release: Core workflow framework for Requirements → Design → Tasks
Quick Start
1. Install (Claude Code Example)
claude mcp add spec-workflow-mcp -s user -- npx -y spec-workflow-mcp@latest
See full installation guide for other clients.
###
8ecc0052dda4OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add spec-workflow-mcp -- npx -y [email protected]
{
"mcpServers": {
"spec-workflow-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
specs-workflow | read |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (6)
const spec = yaml.load(fs.readFileSync(specPath, 'utf8')) as any;
const spec = yaml.load(fs.readFileSync(specPath, 'utf8')) as any;
return yaml.load(specContent) as any;
this.spec = yaml.load(specContent) as OpenApiSpec;
const specPath = path.join(__dirname, '../../../api/spec-workflow.openapi.yaml');
@modelcontextprotocol/sdk, @types/js-yaml, js-yaml, zod, @eslint/js, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
Gates applied: no_behavioural_pass.
8ecc0052dda4full audit observations/trust-audit/mcp-server/kingkongshot__spec-workflow.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 8ecc0052dda4 | BLOCK | D | 66 | first audit |
Questions
What is the Spec Workflow MCP server?
Intelligent spec workflow management MCP server
What tools does Spec Workflow expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Spec Workflow safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (66/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Spec Workflow need?
No credential environment variables were found in its source, so it appears to need none.
How does Spec Workflow run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as spec-workflow-mcp at 1.0.8.
How current is this page?
The grade is for one exact copy of the source (8ecc0052dda4), read on 2026-10-07. The repository is watched and re-audited when it changes.