Github Project ManagerCAUTION
MCP server for AI-powered GitHub project management — 20 tools, 169 actions, agent swarm orchestration, GitHub Actions/Releases/Branches, MCP Resources & Prompts, PRD-to-issues pipeline
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The agentic task substrate for AI coding agents. An MCP server that turns GitHub Projects v2 into a fully autonomous project management platform — AI agents self-assign work, track progress, review each other, and ship code, all backed by GitHub-native storage.
Use case: You have AI agents (Claude Code, Codex, Cursor, Windsurf, Roo). They need a task backbone. This is it.
[](https://www.npmjs.com/package/mcp-github-project-manager) [](https://opensource.org/licenses/MIT) [](https://nodejs.org/)
Overview
This MCP server implements the Model Context Protocol to provide a complete agentic project management layer over GitHub Projects v2. AI agents register, self-assign tasks, coordinate via heartbeats, submit work products for review, and operate within token budgets — all through 20 compound tools exposing 169 actions. Human project managers get AI-powered PRD generation, sprint planning, issue triage, and roadmap creation. Everything is backed by GitHub-native storage (issues, project fields, comments) — no external infrastructure required.
Why This Exists
AI coding agents are powerful but stateless — they don't know what to work on next, can't coordinate with other agents, and have no persistent task memory. This MCP server solves th
e54c0616a31cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-github-project-manager --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env GITHUB_TOKEN=${GITHUB_TOKEN} --env GOOGLE_API_KEY=${GOOGLE_API_KEY} --env OPENAI_API_KEY=${OPENAI_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"mcp-github-project-manager": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"GITHUB_TOKEN": "${GITHUB_TOKEN}",
"GOOGLE_API_KEY": "${GOOGLE_API_KEY}",
"OPENAI_API_KEY": "${OPENAI_API_KEY}"
}
}
}
}Exposed tools (177)
108 read · 52 write · 17 destructive. Blast radius: 17 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Admin | read | System administrator |
Content | read | Main content based on example |
Custom | read | Test |
Developer | read | Creates and tracks development tasks |
Development | read | Core development phase |
Executive | read | C-level decision makers |
First | read | Test |
Fixable | read | Test |
Foundation | read | Build core infrastructure |
Integration | read | Connect external services |
User | read | A user |
add_feature | write | Add a new feature to an existing PRD or project, analyze its impact, and expand it into actionable tasks with complete lifecycle management |
add_issues_to_sprint | write | Add issues to an existing sprint |
add_project_item | write | Add an item to a GitHub project |
add_sub_issue | write | Adds an existing issue as a sub-issue of a parent issue. Creates a parent-child hierarchy between issues. |
agent_heartbeat | write | Send a heartbeat to report agent liveness and progress. |
agent_manage | write | Agent management: list/deregister agents, get activity, submit work products, get/set budgets. Use the |
agent_work | write | Agent work operations: register agents, checkout/release/complete tasks, send heartbeats, check work status, get task context. Use the |
ai_analyze | write | AI-powered analysis: enrich issues (single/bulk), triage issues, schedule triaging, suggest labels, detect duplicates, find related issues. Use the |
ai_generate | write | AI-powered generation: generate/enhance/parse PRDs, add features, get next tasks, analyze complexity, expand tasks, create traceability matrices. Use the |
ai_plan | read | AI-powered planning: calculate capacity, prioritize backlog, assess risk, suggest sprint composition, generate roadmaps and visualizations. Use the |
analyze_task_complexity | read | Perform detailed AI-powered analysis of task complexity, effort estimation, risk assessment, and provide actionable recommendations |
approve_task | read | Approve a task from the review queue. |
archive_project_item | read | Archive an item in a GitHub project. Archived items are hidden from views but not deleted. |
assess_sprint_risk | read | Analyze sprint plan for potential risks. Identifies scope, dependency, capacity, |
assign_items_to_iteration | read | Bulk assign multiple items to a specific iteration |
bug | read | Bug label |
calculate_sprint_capacity | read | Calculate sprint capacity based on team velocity, availability, and buffer. |
check_work_status | read | Check the status of an agent |
checkout_task | read | Claim the next available task for an agent. |
clear_field_value | destructive | Clear a field value for a GitHub project item. This removes/clears the value for any field type. |
close_project | read | Closes a GitHub ProjectV2. Closed projects are hidden from default views but retain all data and can be reopened. |
complete_task | read | Mark a checked-out task as completed. |
convert_draft_issue | read | Converts a draft issue in a project to a real GitHub issue in the specified repository. The draft |
copy_project_from_template | read | Creates a new project by copying from a template. Copies views, custom fields, draft issues (optional), workflows, and insights. The target owner must be an organization. |
create_automation_rule | write | Create a new automation rule for a GitHub project |
create_draft_issue | write | Create a draft issue in a GitHub project. Draft issues are native to Projects v2 and don |
create_issue | write | Creates an issue |
create_issue_comment | write | Add a comment to a GitHub issue |
create_label | write | Create a new GitHub label |
create_milestone | write | Create a new milestone |
create_project | write | Create a new GitHub project |
create_project_field | write | Create a custom field for a GitHub project |
create_project_view | write | Create a new view for a GitHub project |
create_pull_request | write | Create a new pull request in a GitHub repository |
create_pull_request_review | write | Create a review on a pull request (approve, request changes, or comment) |
create_roadmap | write | Create a project roadmap with milestones and tasks |
create_sprint | write | Create a new development sprint |
create_status_update | write | Create a new status update for a GitHub project. Status updates communicate project progress and can include a status indicator (ON_TRACK, AT_RISK, OFF_TRACK, COMPLETE, INACTIVE), start date, and target date. |
create_traceability_matrix | write | Create a comprehensive requirements traceability matrix linking PRD business requirements → features → use cases → tasks with full bidirectional traceability |
delete_automation_rule | destructive | Delete an automation rule from a project |
delete_draft_issue | destructive | Delete a draft issue from a GitHub project |
delete_issue_comment | destructive | Delete a comment from a GitHub issue |
delete_milestone | destructive | Delete a GitHub milestone |
delete_project | destructive | Delete a GitHub project |
delete_project_view | destructive | Delete a view from a GitHub project |
deregister_agent | destructive | Remove an agent from the orchestration registry. |
detect_duplicates | read | Detect potential duplicate issues using semantic similarity (embeddings). |
disable_automation_rule | write | Disable an automation rule without deleting it |
discover_tools | read | Discover available compound tools, their actions, and parameters. Always available regardless of group filter. |
documentation | read | Documentation changes |
enable_automation_rule | write | Enable a disabled automation rule |
enhance_prd | read | Enhance an existing PRD with AI-powered improvements, adding missing elements, improving clarity, and providing comprehensive analysis |
enhancement | read | New feature request |
enrich_issue | read | Enhance issue with structured sections (Problem/Solution/Context/Impact/AcceptanceCriteria), |
enrich_issues_bulk | read | Bulk AI-powered issue enrichment for multiple issues at once. |
expand_task | read | Break down a complex task into smaller, manageable subtasks with AI-powered analysis, dependency detection, and implementation recommendations |
filter_project_items | read | Filters items in a GitHub ProjectV2 by status, labels, assignee, or type. Note: Filtering is performed client-side as GitHub |
find_related_issues | read | Find related issues by semantic similarity, dependency chains (blocks/blocked-by), |
generate_prd | read | Generate a comprehensive Product Requirements Document (PRD) from a project idea using AI analysis and industry best practices |
generate_roadmap | read | Generate a project roadmap from requirements. Creates phases, milestones, and dependencies |
generate_roadmap_visualization | read | Generate Gantt-ready visualization data for a roadmap. Returns phases, milestones, |
get_agent_activity | read | Get an activity dashboard showing all agents and their current state. |
get_agent_metrics | read | Get orchestration metrics across all agents: throughput, cycle time, |
get_automation_rule | read | Get details of a specific automation rule |
get_budget_status | read | Get the token budget status for an agent. |
get_current_iteration | read | Get the currently active iteration based on today |
get_current_sprint | read | Get the currently active sprint |
get_field_value | read | Get a field value for a GitHub project item. Supports reading all field types: TEXT, NUMBER, DATE, SINGLE_SELECT, ITERATION, MILESTONE, ASSIGNEES, LABELS |
get_issue | read | Get details of a specific GitHub issue |
get_iteration_by_date | read | Find which iteration contains a specific date |
get_iteration_configuration | write | Get iteration field configuration including duration, start date, and list of all iterations |
get_iteration_items | read | Get all items assigned to a specific iteration |
get_milestone_metrics | read | Get progress metrics for a specific milestone |
get_next_task | read | Get AI-powered recommendations for the next task to work on based on priorities, dependencies, team capacity, and current project state |
get_overdue_milestones | read | Get a list of overdue milestones |
get_parent_issue | read | Gets the parent issue for a sub-issue, if any. Returns null if the issue has no parent. |
get_project | read | Get details of a specific GitHub project |
get_project_readme | read | Get the README content of a GitHub project |
get_pull_request | read | Get details of a specific pull request |
get_recent_events | read | Get recent events for GitHub resources |
get_sprint_metrics | read | Get progress metrics for a specific sprint |
get_status_update | write | Get a single status update by its node ID. Returns null if the status update is not found. |
get_task_context | read | Get enriched context for a task/issue. |
get_upcoming_milestones | read | Get a list of upcoming milestones within a time frame |
health_check | read | Check system health and service availability. Returns status of GitHub connection, AI services, and cache. |
help-wanted | read | Extra attention needed |
link_project_to_repository | read | Links a GitHub project to a repository. Items from the repository can be added to the project. |
link_project_to_team | read | Links a GitHub project to a team. Team members will have access to the project. |
list_agents | read | List all registered agents, optionally filtered by role or status. |
list_automation_rules | read | List all automation rules for a GitHub project |
list_issue_comments | read | List all comments on a GitHub issue |
list_issues | read | Lists issues |
list_labels | read | List all GitHub labels |
list_linked_repositories | read | Lists all repositories linked to a project. |
list_linked_teams | read | Lists all teams linked to a project. |
list_milestones | read | List milestones |
list_organization_templates | read | Lists all project templates in an organization. Returns templates with their metadata, including title, description, and URLs. |
list_project_fields | read | List all fields in a GitHub project |
list_project_items | read | List all items in a GitHub project |
list_project_views | read | List all views in a GitHub project |
list_projects | read | List GitHub projects |
list_pull_request_reviews | read | List all reviews on a pull request |
list_pull_requests | read | List pull requests in a GitHub repository |
list_sprints | read | List all sprints |
list_status_updates | read | List status updates for a GitHub project with pagination support. Returns status updates in descending order by creation date. |
list_sub_issues | read | Lists all sub-issues for a parent issue. Returns sub-issues with their positions, summary statistics, and pagination info. |
manage_automation | destructive | Manage Automation Rules: create, update, delete, get, list rules; enable and disable rules. Use the |
manage_branches | destructive | Manage GitHub Branch Protection: get, update, and delete a branch |
manage_events | read | Manage Events: subscribe to project events, get recent events, replay events. Use the |
manage_issues | write | Manage GitHub Issues: create, list, get, update issues; manage comments and drafts; search with advanced filters; manage sub-issues. Use the |
manage_iterations | read | Manage Project Iterations: get configuration, current iteration, items; find by date; assign items. Use the |
manage_labels | write | Manage repository Labels: create and list labels. Use the |
manage_milestones | destructive | Manage Milestones: create, list, update, delete milestones; get metrics; find overdue and upcoming milestones. Use the |
manage_project | destructive | Manage GitHub Projects (v2): create, list, get, update, delete projects; manage readme, fields, views, items; handle templates and link to repos/teams. Use the |
manage_prs | write | Manage Pull Requests: create, get, list, update, merge PRs; list and create reviews. Use the |
manage_releases | destructive | Manage GitHub Releases: create, list, get, update, delete releases; get the latest release. Use the |
manage_sprints | destructive | Manage Sprints: create, list, update sprints; get current sprint; add/remove issues; get metrics and plan. Use the |
manage_status_updates | write | Manage project Status Updates: create, list, and get status updates. Use the |
manage_workflows | write | Manage GitHub Actions Workflows: list workflows, trigger dispatch events, inspect run status and logs, list runs, and cancel runs. Use the |
mark_project_as_template | read | Marks an organization project as a template. Only organization-owned projects can be templates. Templates can be copied to create new projects with the same structure. |
merge_pull_request | write | Merge a pull request using merge, squash, or rebase |
new-label | read | D |
parse_prd | read | Parse a Product Requirements Document (PRD) and generate a comprehensive list of actionable development tasks with AI-powered analysis, similar to claude-task-master functionality |
plan_sprint | read | Plan a new sprint with selected issues |
prioritize_backlog | read | AI-powered backlog prioritization using business value, dependencies, risk, and effort. |
reclaim_stale_tasks | read | Reclaim tasks from agents whose heartbeat has gone stale. |
record_usage | read | Record token usage for an agent |
register_agent | read | Register a new AI agent in the orchestration registry. |
reject_task | read | Reject a task from the review queue. |
release_task | read | Release a previously checked-out task back to the pool. |
remove_issues_from_sprint | destructive | Remove issues from a sprint |
remove_project_item | destructive | Remove an item from a GitHub project |
remove_sub_issue | destructive | Removes a sub-issue from its parent. The issue itself remains, only the parent-child relationship is removed. |
reopen_project | read | Reopens a previously closed GitHub ProjectV2. The project becomes visible in default views again. |
replay_events | read | Replay events from a specific timestamp |
reprioritize_sub_issue | read | Changes the position of a sub-issue within its parent |
schedule_triaging | write | Schedule automated issue triaging to run periodically. |
search_issues_advanced | read | Searches GitHub issues using advanced query syntax with AND/OR operators. Use explicit |
security | read | Security related |
set_agent_budget | write | Set or update the token budget for an agent. |
set_field_value | write | Set a field value for a GitHub project item. Supports all field types: TEXT, NUMBER, DATE, SINGLE_SELECT, ITERATION, MILESTONE, ASSIGNEES, LABELS |
setup_agent_fields | write | Idempotently create the GitHub Project custom fields required for agent |
submit_for_review | write | Submit a checked-out task for review. |
submit_work_product | write | Submit a work product (code changes) for a task. |
subscribe_to_events | read | Subscribe to real-time events for GitHub resources |
suggest_labels | read | Suggest labels for an issue with tiered confidence (high/medium/low), rationale for each suggestion, |
suggest_sprint_composition | read | AI-powered sprint composition suggestion. Selects backlog items that fit capacity |
system | read | System operations: health check and project field setup. Use the |
triage_all_issues | read | Automatically triage all untriaged issues in a project. |
triage_issue | read | AI-powered issue triaging. Classifies issues, assigns priority, and recommends actions. |
unarchive_project_item | read | Unarchive an item in a GitHub project. Brings back a previously archived item. |
unlink_project_from_repository | read | Removes a repository linkage from a project. |
unlink_project_from_team | read | Removes a team linkage from a project. |
unmark_project_as_template | read | Removes template status from a project. The project remains but can no longer be used as a template for creating new projects. |
update_automation_rule | write | Update an existing automation rule |
update_draft_issue | write | Update an existing draft issue in a GitHub project |
update_issue | write | Update a GitHub issue |
update_issue_comment | write | Update an existing comment on a GitHub issue |
update_item_position | write | Reorders an item within a GitHub ProjectV2. If afterId is omitted, the item moves to the first position. Position changes persist across views. |
update_milestone | write | Update a GitHub milestone |
update_project | write | Update an existing GitHub project |
update_project_field | write | Update a custom field in a GitHub project |
update_project_readme | write | Update the README content of a GitHub project |
update_project_view | write | Update a view in a GitHub project |
update_pull_request | write | Update a pull request |
update_sprint | write | Update a development sprint |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (14)
expect(ANTHROPIC_API_KEY).toBe("sk-ant-test-anthropic-key-12345");clear_field_value, delete_automation_rule, delete_draft_issue, delete_issue_comment, delete_milestone, delete_project, delete_project_view, deregister_agent, manage_automation, manage_branches, manage
.env.test
import { ProjectManagementService } from "../../src/services/ProjectManagementService.js";import { ProjectManagementService } from "../../src/services/ProjectManagementService.js";import { ProjectManagementService } from "../../src/services/ProjectManagementService.js";import { Server } from "../../build/index.js";const serverProcess = spawn("node", ["../../build/index.js"], {@ai-sdk/anthropic, @ai-sdk/google, @ai-sdk/openai, @ai-sdk/perplexity, @modelcontextprotocol/server, @octokit/auth-app, @octokit/rest, @types/graphlib
- **Reported tokens** — Token usage asserted by the external agent via the `record_usage` tool. Unverifiable by the server — the agent is trusted to report honestly. Stored as `reportedTokens` on `Age
This MCP server implements the [Model Context Protocol](https://modelcontextprotocol.io) to provide a complete **agentic project management layer** over GitHub Projects v2. AI agents register, self-as
# Full access (default)
This document provides comprehensive documentation for the 20 compound MCP tools exposed by the MCP GitHub Project Manager. Each compound tool groups related actions behind a single `action` parameter
curl -sSL https://raw.githubusercontent.com/steveyegge/beads/main/scripts/install.sh | bash
Gates applied: no_behavioural_pass.
e54c0616a31cfull audit observations/trust-audit/mcp-server/kunwarvivek__github-project-manager.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | e54c0616a31c | CAUTION | B | 89 | first audit |
Questions
What is the Github Project Manager MCP server?
MCP server for AI-powered GitHub project management — 20 tools, 169 actions, agent swarm orchestration, GitHub Actions/Releases/Branches, MCP Resources & Prompts, PRD-to-issues pipeline
What tools does Github Project Manager expose?
177 in total: 108 read-only, 52 that write, and 17 that can delete or overwrite (clear_field_value, delete_automation_rule, delete_draft_issue, delete_issue_comment, delete_milestone). Every one is listed on this page with its risk.
Is Github Project Manager safe to connect to an agent?
With care. The audit graded it B (89/100) and found 14 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 17 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Github Project Manager need?
It reads ANTHROPIC_API_KEY, GITHUB_TOKEN, GOOGLE_API_KEY, OPENAI_API_KEY and PERPLEXITY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (e54c0616a31c), read on 2026-10-07. The repository is watched and re-audited when it changes.