Atlas / MCP servers / pimzino / Agentic Tools

Agentic ToolsSAFE

mcp/pimzino/agentic-tools

A comprehensive Model Context Protocol (MCP) server providing AI assistants with powerful task management and agent memories capabilities with project-specific storage.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
29 16r · 9w · 4d
Transport
stdio
License
MIT
Stars
88
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://badge.fury.io/js/@pimzino%2Fagentic-tools-mcp) [](https://www.npmjs.com/package/@pimzino/agentic-tools-mcp) [](https://github.com/Pimzino/agentic-tools-mcp/stargazers) [](https://github.com/Pimzino/agentic-tools-mcp/blob/main/LICENSE) [](https://nodejs.org/)

A comprehensive Model Context Protocol (MCP) server providing AI assistants with powerful advanced task management and agent memories capabilities with project-specific storage.

🔗 Ecosystem

This MCP server is part of a complete task and memory management ecosystem:

  • 🖥️ [VS Code Extension](https://github.com/Pimzino/agentic-tools-mcp-companion) - Beautiful GUI interface for managing tasks and memories directly in VS Code
  • ⚡ MCP Server (this repository) - Advanced AI agent tools and API for intelligent task management
💡 Pro Tip: Use both together for the ultimate productivity experience! The VS Code extension provides a visual interface while the MCP server enables AI assistant integration with advanced features like PRD parsing, task recommendations, and research capabilities.

Features

🎯 Advanced Task Management System with Unlimited Hierarchy (v1.8.0)

  • Projects: Organize work into distinct projects with descriptions
  • Unified Task Model: Single task interface supporting unlimited nesting depth
  • Unlimited Hierarchy: Tasks → Subtasks → Sub-subtasks → infinite depth nesting
  • Rich Features at All Levels: Every task gets priority, complexity, dependencies, tags, and time tracking
  • Parent-Child Relationships: Flexible hi
Read from source at commit 8d6eee77e69bOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add agentic-tools-mcp -- npx -y @pimzino/[email protected]
claude-desktop
{
  "mcpServers": {
    "agentic-tools-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@pimzino/[email protected]"
      ]
    }
  }
}
03

Exposed tools (29)

16 read · 9 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
analyze_task_complexityreadAnalyze task complexity and suggest breaking down overly complex tasks into smaller, manageable subtasks. Intelligent complexity analysis feature for better productivity and progress tracking.
create_memorywriteCreate a new memory in the agent memories system
create_projectwriteCreate a new project in the task management system
create_subtaskwriteCreate a new subtask within a specific task
create_taskwriteCreate a new task within a specific project. Supports unlimited nesting depth - set parentId to create subtasks, sub-subtasks, etc. Leave parentId empty for top-level tasks.
delete_memorydestructiveDelete a memory by ID (requires confirmation)
delete_projectdestructiveDelete a project and all its associated tasks and subtasks. This action cannot be undone.
delete_subtaskdestructiveDelete a subtask. This action cannot be undone.
delete_taskdestructiveDelete a task and all its associated subtasks. This action cannot be undone.
generate_research_queriesreadGenerate intelligent, targeted web search queries for task research. Provides structured search strategies to help AI agents find the most relevant information efficiently.
get_memoryreadGet a specific memory by its ID
get_next_task_recommendationreadGet intelligent recommendations for the next task to work on based on dependencies, priorities, complexity, and current project status. Smart task recommendation engine for optimal workflow management.
get_projectreadGet detailed information about a specific project by its ID
get_subtaskreadGet detailed information about a specific subtask by its ID
get_taskreadGet detailed information about a specific task by its ID
infer_task_progressreadAnalyze the codebase to infer which tasks appear to be completed based on code changes, file creation, and implementation evidence. Intelligent progress inference feature for automatic task completion tracking.
list_memoriesreadList memories with optional filtering by category and limit
list_projectsreadView all projects in the task management system
list_subtasksreadView subtasks, optionally filtered by task ID or project ID
list_tasksreadView tasks in hierarchical tree format. Filter by projectId (required) and/or parentId. Use parentId=null for top-level tasks, or specific parentId for subtasks.
migrate_subtasksreadMigrate existing subtasks to the unified task model. This tool converts all subtasks to tasks with parentId for unlimited nesting depth. Run this once after upgrading to ensure data compatibility.
move_taskwriteMove a task to a different parent in the hierarchy. Set newParentId to move under another task, or leave empty to move to top level. Supports unlimited nesting depth.
parse_prdreadParse a Product Requirements Document (PRD) and automatically generate structured tasks with dependencies, priorities, and complexity estimates. This tool analyzes PRD content and creates a comprehensive task breakdown with intelligent analysis.
research_taskreadGuide the AI agent to perform comprehensive web research for a task, with intelligent research suggestions and automatic memory storage of findings. Combines web research capabilities with local knowledge caching.
search_memoriesreadSearch memories by text content matching
update_memorywriteUpdate an existing memory\
update_projectwriteUpdate the name and/or description of an existing project
update_subtaskwriteUpdate the name, details, and/or completion status of an existing subtask
update_taskwriteUpdate task properties including name, details, parent relationship (parentId), completion status, dependencies, priority, complexity, status, tags, and time estimates. Use parentId to move tasks within the hierarchy.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (7)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_memory, delete_project, delete_subtask, delete_task
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/agent-memories/tools/memories/create.ts:3
import { MemoryStorage } from '../../storage/storage.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/agent-memories/tools/memories/create.ts:4
import { Memory } from '../../models/memory.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/agent-memories/tools/memories/delete.ts:2
import { MemoryStorage } from '../../storage/storage.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/agent-memories/tools/memories/get.ts:2
import { MemoryStorage } from '../../storage/storage.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/features/agent-memories/tools/memories/list.ts:2
import { MemoryStorage } from '../../storage/storage.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 8d6eee77e69bfull audit observations/trust-audit/mcp-server/pimzino__agentic-tools.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-078d6eee77e69bSAFEB89first audit
06

Questions

What is the Agentic Tools MCP server?

A comprehensive Model Context Protocol (MCP) server providing AI assistants with powerful task management and agent memories capabilities with project-specific storage.

What tools does Agentic Tools expose?

29 in total: 16 read-only, 9 that write, and 4 that can delete or overwrite (delete_memory, delete_project, delete_subtask, delete_task). Every one is listed on this page with its risk.

Is Agentic Tools safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Agentic Tools need?

No credential environment variables were found in its source, so it appears to need none.

How does Agentic Tools run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @pimzino/agentic-tools-mcp at 1.8.1.

How current is this page?

The grade is for one exact copy of the source (8d6eee77e69b), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement