Atlas / MCP servers / kunwarvivek / Github Project Manager

Github Project ManagerCAUTION

mcp/kunwarvivek/github-project-manager

MCP server for AI-powered GitHub project management — 20 tools, 169 actions, agent swarm orchestration, GitHub Actions/Releases/Branches, MCP Resources & Prompts, PRD-to-issues pipeline

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
177 108r · 52w · 17d
Transport
—
License
MIT
Stars
101
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The agentic task substrate for AI coding agents. An MCP server that turns GitHub Projects v2 into a fully autonomous project management platform — AI agents self-assign work, track progress, review each other, and ship code, all backed by GitHub-native storage.

Use case: You have AI agents (Claude Code, Codex, Cursor, Windsurf, Roo). They need a task backbone. This is it.

[](https://www.npmjs.com/package/mcp-github-project-manager) [](https://opensource.org/licenses/MIT) [](https://nodejs.org/)

Overview

This MCP server implements the Model Context Protocol to provide a complete agentic project management layer over GitHub Projects v2. AI agents register, self-assign tasks, coordinate via heartbeats, submit work products for review, and operate within token budgets — all through 20 compound tools exposing 169 actions. Human project managers get AI-powered PRD generation, sprint planning, issue triage, and roadmap creation. Everything is backed by GitHub-native storage (issues, project fields, comments) — no external infrastructure required.

Why This Exists

AI coding agents are powerful but stateless — they don't know what to work on next, can't coordinate with other agents, and have no persistent task memory. This MCP server solves th

Read from source at commit e54c0616a31cOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-github-project-manager --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env GOOGLE_API_KEY=${GOOGLE_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-github-project-manager": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "GITHUB_TOKEN": "${GITHUB_TOKEN}",
        "GOOGLE_API_KEY": "${GOOGLE_API_KEY}",
        "OPENAI_API_KEY": "${OPENAI_API_KEY}"
      }
    }
  }
}
03

Exposed tools (177)

108 read · 52 write · 17 destructive. Blast radius: 17 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
AdminreadSystem administrator
ContentreadMain content based on example
CustomreadTest
DeveloperreadCreates and tracks development tasks
DevelopmentreadCore development phase
ExecutivereadC-level decision makers
FirstreadTest
FixablereadTest
FoundationreadBuild core infrastructure
IntegrationreadConnect external services
UserreadA user
add_featurewriteAdd a new feature to an existing PRD or project, analyze its impact, and expand it into actionable tasks with complete lifecycle management
add_issues_to_sprintwriteAdd issues to an existing sprint
add_project_itemwriteAdd an item to a GitHub project
add_sub_issuewriteAdds an existing issue as a sub-issue of a parent issue. Creates a parent-child hierarchy between issues.
agent_heartbeatwriteSend a heartbeat to report agent liveness and progress.
agent_managewriteAgent management: list/deregister agents, get activity, submit work products, get/set budgets. Use the
agent_workwriteAgent work operations: register agents, checkout/release/complete tasks, send heartbeats, check work status, get task context. Use the
ai_analyzewriteAI-powered analysis: enrich issues (single/bulk), triage issues, schedule triaging, suggest labels, detect duplicates, find related issues. Use the
ai_generatewriteAI-powered generation: generate/enhance/parse PRDs, add features, get next tasks, analyze complexity, expand tasks, create traceability matrices. Use the
ai_planreadAI-powered planning: calculate capacity, prioritize backlog, assess risk, suggest sprint composition, generate roadmaps and visualizations. Use the
analyze_task_complexityreadPerform detailed AI-powered analysis of task complexity, effort estimation, risk assessment, and provide actionable recommendations
approve_taskreadApprove a task from the review queue.
archive_project_itemreadArchive an item in a GitHub project. Archived items are hidden from views but not deleted.
assess_sprint_riskreadAnalyze sprint plan for potential risks. Identifies scope, dependency, capacity,
assign_items_to_iterationreadBulk assign multiple items to a specific iteration
bugreadBug label
calculate_sprint_capacityreadCalculate sprint capacity based on team velocity, availability, and buffer.
check_work_statusreadCheck the status of an agent
checkout_taskreadClaim the next available task for an agent.
clear_field_valuedestructiveClear a field value for a GitHub project item. This removes/clears the value for any field type.
close_projectreadCloses a GitHub ProjectV2. Closed projects are hidden from default views but retain all data and can be reopened.
complete_taskreadMark a checked-out task as completed.
convert_draft_issuereadConverts a draft issue in a project to a real GitHub issue in the specified repository. The draft
copy_project_from_templatereadCreates a new project by copying from a template. Copies views, custom fields, draft issues (optional), workflows, and insights. The target owner must be an organization.
create_automation_rulewriteCreate a new automation rule for a GitHub project
create_draft_issuewriteCreate a draft issue in a GitHub project. Draft issues are native to Projects v2 and don
create_issuewriteCreates an issue
create_issue_commentwriteAdd a comment to a GitHub issue
create_labelwriteCreate a new GitHub label
create_milestonewriteCreate a new milestone
create_projectwriteCreate a new GitHub project
create_project_fieldwriteCreate a custom field for a GitHub project
create_project_viewwriteCreate a new view for a GitHub project
create_pull_requestwriteCreate a new pull request in a GitHub repository
create_pull_request_reviewwriteCreate a review on a pull request (approve, request changes, or comment)
create_roadmapwriteCreate a project roadmap with milestones and tasks
create_sprintwriteCreate a new development sprint
create_status_updatewriteCreate a new status update for a GitHub project. Status updates communicate project progress and can include a status indicator (ON_TRACK, AT_RISK, OFF_TRACK, COMPLETE, INACTIVE), start date, and target date.
create_traceability_matrixwriteCreate a comprehensive requirements traceability matrix linking PRD business requirements → features → use cases → tasks with full bidirectional traceability
delete_automation_ruledestructiveDelete an automation rule from a project
delete_draft_issuedestructiveDelete a draft issue from a GitHub project
delete_issue_commentdestructiveDelete a comment from a GitHub issue
delete_milestonedestructiveDelete a GitHub milestone
delete_projectdestructiveDelete a GitHub project
delete_project_viewdestructiveDelete a view from a GitHub project
deregister_agentdestructiveRemove an agent from the orchestration registry.
detect_duplicatesreadDetect potential duplicate issues using semantic similarity (embeddings).
disable_automation_rulewriteDisable an automation rule without deleting it
discover_toolsreadDiscover available compound tools, their actions, and parameters. Always available regardless of group filter.
documentationreadDocumentation changes
enable_automation_rulewriteEnable a disabled automation rule
enhance_prdreadEnhance an existing PRD with AI-powered improvements, adding missing elements, improving clarity, and providing comprehensive analysis
enhancementreadNew feature request
enrich_issuereadEnhance issue with structured sections (Problem/Solution/Context/Impact/AcceptanceCriteria),
enrich_issues_bulkreadBulk AI-powered issue enrichment for multiple issues at once.
expand_taskreadBreak down a complex task into smaller, manageable subtasks with AI-powered analysis, dependency detection, and implementation recommendations
filter_project_itemsreadFilters items in a GitHub ProjectV2 by status, labels, assignee, or type. Note: Filtering is performed client-side as GitHub
find_related_issuesreadFind related issues by semantic similarity, dependency chains (blocks/blocked-by),
generate_prdreadGenerate a comprehensive Product Requirements Document (PRD) from a project idea using AI analysis and industry best practices
generate_roadmapreadGenerate a project roadmap from requirements. Creates phases, milestones, and dependencies
generate_roadmap_visualizationreadGenerate Gantt-ready visualization data for a roadmap. Returns phases, milestones,
get_agent_activityreadGet an activity dashboard showing all agents and their current state.
get_agent_metricsreadGet orchestration metrics across all agents: throughput, cycle time,
get_automation_rulereadGet details of a specific automation rule
get_budget_statusreadGet the token budget status for an agent.
get_current_iterationreadGet the currently active iteration based on today
get_current_sprintreadGet the currently active sprint
get_field_valuereadGet a field value for a GitHub project item. Supports reading all field types: TEXT, NUMBER, DATE, SINGLE_SELECT, ITERATION, MILESTONE, ASSIGNEES, LABELS
get_issuereadGet details of a specific GitHub issue
get_iteration_by_datereadFind which iteration contains a specific date
get_iteration_configurationwriteGet iteration field configuration including duration, start date, and list of all iterations
get_iteration_itemsreadGet all items assigned to a specific iteration
get_milestone_metricsreadGet progress metrics for a specific milestone
get_next_taskreadGet AI-powered recommendations for the next task to work on based on priorities, dependencies, team capacity, and current project state
get_overdue_milestonesreadGet a list of overdue milestones
get_parent_issuereadGets the parent issue for a sub-issue, if any. Returns null if the issue has no parent.
get_projectreadGet details of a specific GitHub project
get_project_readmereadGet the README content of a GitHub project
get_pull_requestreadGet details of a specific pull request
get_recent_eventsreadGet recent events for GitHub resources
get_sprint_metricsreadGet progress metrics for a specific sprint
get_status_updatewriteGet a single status update by its node ID. Returns null if the status update is not found.
get_task_contextreadGet enriched context for a task/issue.
get_upcoming_milestonesreadGet a list of upcoming milestones within a time frame
health_checkreadCheck system health and service availability. Returns status of GitHub connection, AI services, and cache.
help-wantedreadExtra attention needed
link_project_to_repositoryreadLinks a GitHub project to a repository. Items from the repository can be added to the project.
link_project_to_teamreadLinks a GitHub project to a team. Team members will have access to the project.
list_agentsreadList all registered agents, optionally filtered by role or status.
list_automation_rulesreadList all automation rules for a GitHub project
list_issue_commentsreadList all comments on a GitHub issue
list_issuesreadLists issues
list_labelsreadList all GitHub labels
list_linked_repositoriesreadLists all repositories linked to a project.
list_linked_teamsreadLists all teams linked to a project.
list_milestonesreadList milestones
list_organization_templatesreadLists all project templates in an organization. Returns templates with their metadata, including title, description, and URLs.
list_project_fieldsreadList all fields in a GitHub project
list_project_itemsreadList all items in a GitHub project
list_project_viewsreadList all views in a GitHub project
list_projectsreadList GitHub projects
list_pull_request_reviewsreadList all reviews on a pull request
list_pull_requestsreadList pull requests in a GitHub repository
list_sprintsreadList all sprints
list_status_updatesreadList status updates for a GitHub project with pagination support. Returns status updates in descending order by creation date.
list_sub_issuesreadLists all sub-issues for a parent issue. Returns sub-issues with their positions, summary statistics, and pagination info.
manage_automationdestructiveManage Automation Rules: create, update, delete, get, list rules; enable and disable rules. Use the
manage_branchesdestructiveManage GitHub Branch Protection: get, update, and delete a branch
manage_eventsreadManage Events: subscribe to project events, get recent events, replay events. Use the
manage_issueswriteManage GitHub Issues: create, list, get, update issues; manage comments and drafts; search with advanced filters; manage sub-issues. Use the
manage_iterationsreadManage Project Iterations: get configuration, current iteration, items; find by date; assign items. Use the
manage_labelswriteManage repository Labels: create and list labels. Use the
manage_milestonesdestructiveManage Milestones: create, list, update, delete milestones; get metrics; find overdue and upcoming milestones. Use the
manage_projectdestructiveManage GitHub Projects (v2): create, list, get, update, delete projects; manage readme, fields, views, items; handle templates and link to repos/teams. Use the
manage_prswriteManage Pull Requests: create, get, list, update, merge PRs; list and create reviews. Use the
manage_releasesdestructiveManage GitHub Releases: create, list, get, update, delete releases; get the latest release. Use the
manage_sprintsdestructiveManage Sprints: create, list, update sprints; get current sprint; add/remove issues; get metrics and plan. Use the
manage_status_updateswriteManage project Status Updates: create, list, and get status updates. Use the
manage_workflowswriteManage GitHub Actions Workflows: list workflows, trigger dispatch events, inspect run status and logs, list runs, and cancel runs. Use the
mark_project_as_templatereadMarks an organization project as a template. Only organization-owned projects can be templates. Templates can be copied to create new projects with the same structure.
merge_pull_requestwriteMerge a pull request using merge, squash, or rebase
new-labelreadD
parse_prdreadParse a Product Requirements Document (PRD) and generate a comprehensive list of actionable development tasks with AI-powered analysis, similar to claude-task-master functionality
plan_sprintreadPlan a new sprint with selected issues
prioritize_backlogreadAI-powered backlog prioritization using business value, dependencies, risk, and effort.
reclaim_stale_tasksreadReclaim tasks from agents whose heartbeat has gone stale.
record_usagereadRecord token usage for an agent
register_agentreadRegister a new AI agent in the orchestration registry.
reject_taskreadReject a task from the review queue.
release_taskreadRelease a previously checked-out task back to the pool.
remove_issues_from_sprintdestructiveRemove issues from a sprint
remove_project_itemdestructiveRemove an item from a GitHub project
remove_sub_issuedestructiveRemoves a sub-issue from its parent. The issue itself remains, only the parent-child relationship is removed.
reopen_projectreadReopens a previously closed GitHub ProjectV2. The project becomes visible in default views again.
replay_eventsreadReplay events from a specific timestamp
reprioritize_sub_issuereadChanges the position of a sub-issue within its parent
schedule_triagingwriteSchedule automated issue triaging to run periodically.
search_issues_advancedreadSearches GitHub issues using advanced query syntax with AND/OR operators. Use explicit
securityreadSecurity related
set_agent_budgetwriteSet or update the token budget for an agent.
set_field_valuewriteSet a field value for a GitHub project item. Supports all field types: TEXT, NUMBER, DATE, SINGLE_SELECT, ITERATION, MILESTONE, ASSIGNEES, LABELS
setup_agent_fieldswriteIdempotently create the GitHub Project custom fields required for agent
submit_for_reviewwriteSubmit a checked-out task for review.
submit_work_productwriteSubmit a work product (code changes) for a task.
subscribe_to_eventsreadSubscribe to real-time events for GitHub resources
suggest_labelsreadSuggest labels for an issue with tiered confidence (high/medium/low), rationale for each suggestion,
suggest_sprint_compositionreadAI-powered sprint composition suggestion. Selects backlog items that fit capacity
systemreadSystem operations: health check and project field setup. Use the
triage_all_issuesreadAutomatically triage all untriaged issues in a project.
triage_issuereadAI-powered issue triaging. Classifies issues, assigns priority, and recommends actions.
unarchive_project_itemreadUnarchive an item in a GitHub project. Brings back a previously archived item.
unlink_project_from_repositoryreadRemoves a repository linkage from a project.
unlink_project_from_teamreadRemoves a team linkage from a project.
unmark_project_as_templatereadRemoves template status from a project. The project remains but can no longer be used as a template for creating new projects.
update_automation_rulewriteUpdate an existing automation rule
update_draft_issuewriteUpdate an existing draft issue in a GitHub project
update_issuewriteUpdate a GitHub issue
update_issue_commentwriteUpdate an existing comment on a GitHub issue
update_item_positionwriteReorders an item within a GitHub ProjectV2. If afterId is omitted, the item moves to the first position. Position changes persist across views.
update_milestonewriteUpdate a GitHub milestone
update_projectwriteUpdate an existing GitHub project
update_project_fieldwriteUpdate a custom field in a GitHub project
update_project_readmewriteUpdate the README content of a GitHub project
update_project_viewwriteUpdate a view in a GitHub project
update_pull_requestwriteUpdate a pull request
update_sprintwriteUpdate a development sprint
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (2 observation(s))
Shell
declared (5 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (14)

MEDIUMHard-coded secrets · secret.anthropic · CWE-798, CWE-321
tests/ai-services/AIServiceFactory.test.ts:142
expect(ANTHROPIC_API_KEY).toBe("sk-ant-test-anthropic-key-12345");
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
clear_field_value, delete_automation_rule, delete_draft_issue, delete_issue_comment, delete_milestone, delete_project, delete_project_view, deregister_agent, manage_automation, manage_branches, manage
Why it matters. 17 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.test
.env.test
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/basic/create-simple-project.ts:17
import { ProjectManagementService } from "../../src/services/ProjectManagementService.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/basic/plan-sprint.ts:19
import { ProjectManagementService } from "../../src/services/ProjectManagementService.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/basic/track-progress.ts:18
import { ProjectManagementService } from "../../src/services/ProjectManagementService.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/integration/nodejs-client.js:11
import { Server } from "../../build/index.js";
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
examples/integration/nodejs-client.js:40
const serverProcess = spawn("node", ["../../build/index.js"], {
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@ai-sdk/anthropic, @ai-sdk/google, @ai-sdk/openai, @ai-sdk/perplexity, @modelcontextprotocol/server, @octokit/auth-app, @octokit/rest, @types/graphlib
Why it matters. 29 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CONTEXT.md:7
- **Reported tokens** — Token usage asserted by the external agent via the `record_usage` tool. Unverifiable by the server — the agent is trusted to report honestly. Stored as `reportedTokens` on `Age
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:15
This MCP server implements the [Model Context Protocol](https://modelcontextprotocol.io) to provide a complete **agentic project management layer** over GitHub Projects v2. AI agents register, self-as
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/CONFIGURATION.md:211
# Full access (default)
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
docs/TOOLS.md:3
This document provides comprehensive documentation for the 20 compound MCP tools exposed by the MCP GitHub Project Manager. Each compound tool groups related actions behind a single `action` parameter
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
.beads/README.md:64
curl -sSL https://raw.githubusercontent.com/steveyegge/beads/main/scripts/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha e54c0616a31cfull audit observations/trust-audit/mcp-server/kunwarvivek__github-project-manager.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07e54c0616a31cCAUTIONB89first audit
06

Questions

What is the Github Project Manager MCP server?

MCP server for AI-powered GitHub project management — 20 tools, 169 actions, agent swarm orchestration, GitHub Actions/Releases/Branches, MCP Resources & Prompts, PRD-to-issues pipeline

What tools does Github Project Manager expose?

177 in total: 108 read-only, 52 that write, and 17 that can delete or overwrite (clear_field_value, delete_automation_rule, delete_draft_issue, delete_issue_comment, delete_milestone). Every one is listed on this page with its risk.

Is Github Project Manager safe to connect to an agent?

With care. The audit graded it B (89/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 17 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Github Project Manager need?

It reads ANTHROPIC_API_KEY, GITHUB_TOKEN, GOOGLE_API_KEY, OPENAI_API_KEY and PERPLEXITY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (e54c0616a31c), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement