Atlas / MCP servers / kingkongshot / Spec Workflow

Spec WorkflowBLOCK

mcp/kingkongshot/spec-workflow

Intelligent spec workflow management MCP server

Verdict
BLOCK
Grade
D
Trust score
66 /100
Exposed tools
1 1r · 0w · 0d
Transport
stdio
License
MIT
Stars
127
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/spec-workflow-mcp) [](https://opensource.org/licenses/MIT) [](https://modelcontextprotocol.com)

English | 简体中文

Guide AI to systematically complete software development through a structured Requirements → Design → Tasks workflow, ensuring code implementation stays aligned with business needs.

Why Use It?

❌ Without Spec Workflow

  • AI jumps randomly between tasks, lacking systematic approach
  • Requirements disconnect from actual code implementation
  • Scattered documentation, difficult to track project progress
  • Missing design decision records

✅ With Spec Workflow

  • AI completes tasks sequentially, maintaining focus and context
  • Complete traceability from user stories to code implementation
  • Standardized document templates with automatic progress management
  • Each stage requires confirmation, ensuring correct direction
  • Persistent progress: Continue from where you left off with check, even in new conversations

Recent Updates

v1.0.7 - 🎯 Improved reliability for most models to manage tasks with spec workflow v1.0.6 - ✨ Batch task completion: Complete multiple tasks at once for faster progress on large projects v1.0.5 - 🐛 Edge case fixes: Distinguish between "task not found" and "task already completed" to prevent workflow interruption v1.0.4 - ✅ Task management: Added task completion tracking for systematic project progression v1.0.3 - 🎉 Initial release: Core workflow framework for Requirements → Design → Tasks

Quick Start

1. Install (Claude Code Example)

claude mcp add spec-workflow-mcp -s user -- npx -y spec-workflow-mcp@latest

See full installation guide for other clients.

###

Read from source at commit 8ecc0052dda4OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add spec-workflow-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "spec-workflow-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (1)

1 read · 0 write · 0 destructive.

ToolRiskDescription
specs-workflowread
04

Trust audit

BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (4 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (6)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/generateOpenApiWebUI.ts:18
const spec = yaml.load(fs.readFileSync(specPath, 'utf8')) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/generateTypes.ts:17
const spec = yaml.load(fs.readFileSync(specPath, 'utf8')) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
scripts/validateOpenApi.ts:18
return yaml.load(specContent) as any;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/features/shared/openApiLoader.ts:92
this.spec = yaml.load(specContent) as OpenApiSpec;
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/shared/openApiLoader.ts:90
const specPath = path.join(__dirname, '../../../api/spec-workflow.openapi.yaml');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, @types/js-yaml, js-yaml, zod, @eslint/js, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 8ecc0052dda4full audit observations/trust-audit/mcp-server/kingkongshot__spec-workflow.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-078ecc0052dda4BLOCKD66first audit
06

Questions

What is the Spec Workflow MCP server?

Intelligent spec workflow management MCP server

What tools does Spec Workflow expose?

1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Spec Workflow safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (66/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Spec Workflow need?

No credential environment variables were found in its source, so it appears to need none.

How does Spec Workflow run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as spec-workflow-mcp at 1.0.8.

How current is this page?

The grade is for one exact copy of the source (8ecc0052dda4), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement