TaskFlowBLOCK
A task management Model Context Protocol (MCP) server that helps AI assistants break down user requests into manageable tasks with subtasks, dependencies, and notes. Enforces a structured workflow with user approval steps.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A task management Model Context Protocol (MCP) server for planning and executing tasks with AI assistants.
[](https://mseep.ai/app/pinkpixel-dev-taskflow-mcp)
🌟 Overview
TaskFlow MCP is a specialized server that helps AI assistants break down user requests into manageable tasks and track their completion. It enforces a structured workflow with user approval steps to ensure tasks are properly tracked and users maintain control over the process.
✨ Features
- 📋 Task Planning: Break down complex requests into manageable tasks
- 🔍 Subtasks: Divide tasks into smaller, more manageable subtasks
- 📊 Progress Tracking: Track the status of tasks, subtasks, and requests with visual progress tables
- 👍 User Approval: Enforce user approval steps to ensure quality and control
- 💾 Persistence: Save tasks and requests to disk for persistence across sessions
- 🔄 Flexible Management: Add, update, or delete tasks and subtasks as needed
- 📝 Detailed Reporting: View task details and progress tables
- 📤 Export Options: Export task plans and status reports in Markdown, JSON, or HTML formats
- 📦 Dependencies: Track project and task-level dependencies with version information
- 📌 Notes: Add project-level notes for important information and preferences
- 📄 YAML Support: Save tasks in YAML format for better handling of multiline content
- 🛡️ Robust Text Handling: Comprehensive newline sanitization for reliable data persistence
- 🎯
72450d6b8e32OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add taskflow-mcp -- npx -y @pinkpixel/[email protected]
{
"mcpServers": {
"taskflow-mcp": {
"command": "npx",
"args": [
"-y",
"@pinkpixel/[email protected]"
]
}
}
}Exposed tools (24)
11 read · 9 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_dependency | write | Add a dependency to a request or task.\n\n |
add_note | write | Add a note to a request. Notes can contain important information about the project, such as user preferences or guidelines.\n\n |
add_subtasks | write | Add subtasks to an existing task. Provide |
add_tasks_to_request | write | Add new tasks to an existing request. This allows extending a request with additional tasks.\n\n |
archive_completed_requests | read | Archive completed requests to a separate file to keep the active tasks file clean.\n\n |
delete_note | destructive | Delete a note from a request.\n\n |
delete_subtask | destructive | Delete a subtask from a task. Provide |
delete_task | destructive | Delete a specific task from a request. Only uncompleted tasks can be deleted.\n\n |
export_task_status | read | Export the current status of all tasks in a request to a file.\n\n |
get_next_task | read | Given a |
get_prompts | read | Get the current prompts configuration including instructions, taskPrefix, and taskSuffix settings.\n\n |
list_archived_requests | read | List archived requests with optional search and filtering capabilities.\n\n |
list_requests | read | List all requests with their basic information and summary of tasks. This provides a quick overview of all requests in the system. |
mark_subtask_done | read | Mark a subtask as done. Provide |
mark_task_done | read | Mark a given task as done after you |
open_task_details | read | Get details of a specific task by |
plan_task | read | Register a new user request and plan its associated tasks. You must provide |
remove_prompts | destructive | Remove the entire prompts configuration or specific fields from it.\n\n |
restore_archived_request | read | Restore a specific archived request back to the active tasks file.\n\n |
set_prompts | write | Set the global prompts configuration with instructions, taskPrefix, and/or taskSuffix.\n\n |
update_note | write | Update an existing note |
update_prompts | write | Update specific parts of the prompts configuration without replacing the entire object.\n\n |
update_subtask | write | Update a subtask |
update_task | write | Update an existing task |
Trust audit
BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- none-observed
- Shell
- declared (1 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
const parsed = yaml.load(raw);
delete_note, delete_subtask, delete_task, remove_prompts
dockerBuildPath: ../../
@modelcontextprotocol/sdk, chalk, docker-cli, glob, js-yaml, zod, zod-to-json-schema, @types/js-yaml
icon.png
Gates applied: no_behavioural_pass.
72450d6b8e32full audit observations/trust-audit/mcp-server/pinkpixel-dev__taskflow-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 72450d6b8e32 | BLOCK | D | 69 | first audit |
Questions
What is the TaskFlow MCP server?
A task management Model Context Protocol (MCP) server that helps AI assistants break down user requests into manageable tasks with subtasks, dependencies, and notes. Enforces a structured workflow with user approval steps.
What tools does TaskFlow expose?
24 in total: 11 read-only, 9 that write, and 4 that can delete or overwrite (delete_note, delete_subtask, delete_task, remove_prompts). Every one is listed on this page with its risk.
Is TaskFlow safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does TaskFlow need?
No credential environment variables were found in its source, so it appears to need none.
How does TaskFlow run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @pinkpixel/taskflow-mcp at 1.5.0.
How current is this page?
The grade is for one exact copy of the source (72450d6b8e32), read on 2026-10-08. The repository is watched and re-audited when it changes.