Atlas / MCP servers / pinkpixel-dev / TaskFlow

TaskFlowBLOCK

mcp/pinkpixel-dev/taskflow-1

A task management Model Context Protocol (MCP) server that helps AI assistants break down user requests into manageable tasks with subtasks, dependencies, and notes. Enforces a structured workflow with user approval steps.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Exposed tools
24 11r · 9w · 4d
Transport
stdio
License
MIT
Stars
29
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A task management Model Context Protocol (MCP) server for planning and executing tasks with AI assistants.

[](https://mseep.ai/app/pinkpixel-dev-taskflow-mcp)

🌟 Overview

TaskFlow MCP is a specialized server that helps AI assistants break down user requests into manageable tasks and track their completion. It enforces a structured workflow with user approval steps to ensure tasks are properly tracked and users maintain control over the process.

✨ Features

  • 📋 Task Planning: Break down complex requests into manageable tasks
  • 🔍 Subtasks: Divide tasks into smaller, more manageable subtasks
  • 📊 Progress Tracking: Track the status of tasks, subtasks, and requests with visual progress tables
  • 👍 User Approval: Enforce user approval steps to ensure quality and control
  • 💾 Persistence: Save tasks and requests to disk for persistence across sessions
  • 🔄 Flexible Management: Add, update, or delete tasks and subtasks as needed
  • 📝 Detailed Reporting: View task details and progress tables
  • 📤 Export Options: Export task plans and status reports in Markdown, JSON, or HTML formats
  • 📦 Dependencies: Track project and task-level dependencies with version information
  • 📌 Notes: Add project-level notes for important information and preferences
  • 📄 YAML Support: Save tasks in YAML format for better handling of multiline content
  • 🛡️ Robust Text Handling: Comprehensive newline sanitization for reliable data persistence
  • 🎯
Read from source at commit 72450d6b8e32OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add taskflow-mcp -- npx -y @pinkpixel/[email protected]
claude-desktop
{
  "mcpServers": {
    "taskflow-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@pinkpixel/[email protected]"
      ]
    }
  }
}
03

Exposed tools (24)

11 read · 9 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_dependencywriteAdd a dependency to a request or task.\n\n
add_notewriteAdd a note to a request. Notes can contain important information about the project, such as user preferences or guidelines.\n\n
add_subtaskswriteAdd subtasks to an existing task. Provide
add_tasks_to_requestwriteAdd new tasks to an existing request. This allows extending a request with additional tasks.\n\n
archive_completed_requestsreadArchive completed requests to a separate file to keep the active tasks file clean.\n\n
delete_notedestructiveDelete a note from a request.\n\n
delete_subtaskdestructiveDelete a subtask from a task. Provide
delete_taskdestructiveDelete a specific task from a request. Only uncompleted tasks can be deleted.\n\n
export_task_statusreadExport the current status of all tasks in a request to a file.\n\n
get_next_taskreadGiven a
get_promptsreadGet the current prompts configuration including instructions, taskPrefix, and taskSuffix settings.\n\n
list_archived_requestsreadList archived requests with optional search and filtering capabilities.\n\n
list_requestsreadList all requests with their basic information and summary of tasks. This provides a quick overview of all requests in the system.
mark_subtask_donereadMark a subtask as done. Provide
mark_task_donereadMark a given task as done after you
open_task_detailsreadGet details of a specific task by
plan_taskreadRegister a new user request and plan its associated tasks. You must provide
remove_promptsdestructiveRemove the entire prompts configuration or specific fields from it.\n\n
restore_archived_requestreadRestore a specific archived request back to the active tasks file.\n\n
set_promptswriteSet the global prompts configuration with instructions, taskPrefix, and/or taskSuffix.\n\n
update_notewriteUpdate an existing note
update_promptswriteUpdate specific parts of the prompts configuration without replacing the entire object.\n\n
update_subtaskwriteUpdate a subtask
update_taskwriteUpdate an existing task
04

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

HIGHCode injection · code.deserialize · CWE-78, CWE-94, CWE-95
src/utils/fileFormat.ts:11
const parsed = yaml.load(raw);
Why it matters. deserialises untrusted bytes into live objects
Fix. use json or yaml.safe_load
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_note, delete_subtask, delete_task, remove_prompts
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
smithery.yaml:2
dockerBuildPath: ../../
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, chalk, docker-cli, glob, js-yaml, zod, zod-to-json-schema, @types/js-yaml
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
icon.png
icon.png
Why it matters. 1035398 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 72450d6b8e32full audit observations/trust-audit/mcp-server/pinkpixel-dev__taskflow-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0872450d6b8e32BLOCKD69first audit
06

Questions

What is the TaskFlow MCP server?

A task management Model Context Protocol (MCP) server that helps AI assistants break down user requests into manageable tasks with subtasks, dependencies, and notes. Enforces a structured workflow with user approval steps.

What tools does TaskFlow expose?

24 in total: 11 read-only, 9 that write, and 4 that can delete or overwrite (delete_note, delete_subtask, delete_task, remove_prompts). Every one is listed on this page with its risk.

Is TaskFlow safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (69/100) and found 1 critical or high issue in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does TaskFlow need?

No credential environment variables were found in its source, so it appears to need none.

How does TaskFlow run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @pinkpixel/taskflow-mcp at 1.5.0.

How current is this page?

The grade is for one exact copy of the source (72450d6b8e32), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement