Atlas / MCP servers / planexeorg / PlanExe

PlanExeBLOCK

mcp/planexeorg/planexe

Create a plan from a description in minutes

Verdict
BLOCK
Grade
D
Trust score
63 /100
Exposed tools
—
Transport
streamable-http
License
MIT
Stars
401
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

<source media="(prefers-color-scheme: dark)" srcset="docs/hero/planexe-hero-v1-grid-dark.svg"> <img src="docs/hero/planexe-hero-v1-grid-light.svg" alt="The PlanExe icon is the P character and E character" width="100%">

Planning complex projects should not require a consulting-firm budget.

Turn a complex project brief into an editable planning baseline in about 15 minutes.

Create an account | See example plans | Getting started guide

Why PlanExe exists

Good ideas are not limited to people and organizations that can afford a large consulting engagement. Turning an ambitious idea into a coherent project, however, normally requires substantial time, specialist knowledge, stakeholder interviews, and repeated synthesis.

PlanExe is open-source software for people and AI agents that need to plan complex projects. Describe a project in plain language and PlanExe creates a structured first-pass plan: the assumptions to challenge, decisions to make, work to coordinate, risks to investigate, and questions that must be answered before execution.

The result is not a substitute for stakeholder participation or professional sign-off. It is a way to begin with a broad, inspectable planning baseline instead of a blank page.

What PlanExe does

PlanExe examines a project

Read from source at commit 1857824dd70aOBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add PlanExe --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env ANTHROPIC_OAUTHTOKEN=${ANTHROPIC_OAUTHTOKEN} --env OPENROUTER_API_KEY=${OPENROUTER_API_KEY} --env PLANEXE_API_KEY_SECRET=${PLANEXE_API_KEY_SECRET} -- uvx PlanExe
claude-desktop
{
  "mcpServers": {
    "PlanExe": {
      "command": "uvx",
      "args": [
        "PlanExe"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "ANTHROPIC_OAUTHTOKEN": "${ANTHROPIC_OAUTHTOKEN}",
        "OPENROUTER_API_KEY": "${OPENROUTER_API_KEY}",
        "PLANEXE_API_KEY_SECRET": "${PLANEXE_API_KEY_SECRET}"
      }
    }
  }
}
03

Trust audit

BLOCKgrade D · trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (10 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
found

Findings (25)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/proposals/ensemble-judge-refinement.md:124
- Not a jailbreak mechanism
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.read_system · CWE-94, CWE-1427
experiments/napkin_math/.claude/skills/extract-parameters-from-full/SKILL.md:24
3. **Read the report file.** For large HTML reports, read the whole file; the system prompt's hard limits (≤8 key_values, ≤5 of each list, ≤25-word comments) keep output bounded regardless of input si
HIGHPrompt injection · prompt.read_system · CWE-94, CWE-1427
experiments/napkin_math/.claude/skills/run-scenarios/SKILL.md:49
## Output Shape (re-stated for emphasis — see system prompt for full detail)
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/proposals/06-adopt-on-the-fly.md:1
# Plan: "Smart On The Fly" Agent Routing (Business vs Software)
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.developer-example:62
# PLANEXE_MCP_PUBLIC_BASE_URL='http://192.168.1.40:8001'
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.developer-example:63
# PLANEXE_MCP_CORS_ORIGINS='http://localhost,http://127.0.0.1'
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.docker-example:51
# PLANEXE_MCP_PUBLIC_BASE_URL='http://192.168.1.40:8001'
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
.env.docker-example:52
# PLANEXE_MCP_CORS_ORIGINS='http://localhost,http://127.0.0.1'
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
worker_plan/worker_plan_internal/swot/swot_analysis.py:145
rows.append("\n## Missing Information 🧩🤷♂️🤷♀️")
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/proposals/64-post-plan-orchestration-layer.md:1170
DATABASE_URL: postgres://planexe:planexe@postgres:5432/orchestration
MEDIUMHard-coded secrets · secret.db_uri · CWE-798, CWE-321
docs/proposals/64-post-plan-orchestration-layer.md:1232
DATABASE_URL=postgres://planexe:planexe@localhost:5432/orchestration
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.developer-example
.env.developer-example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.env.docker-example
.env.docker-example
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/AGENTS.md:90
3. Run `python serve.py` to serve `site/` at `http://127.0.0.1:18525/`.
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docker-compose.md:7
- Shared host files: `.env` and `./llm_config/` mounted read-only; `.env` is also loaded via `env_file`.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/ai_providers/openrouter.md:45
Open the `.env` file in a text editor and insert your OpenRouter API key. Like this:
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/install_developer.md:17
Update `OPENROUTER_API_KEY` with your open router api key.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
llm_config/AGENTS.md:73
resolved at load time from `.env` via `PlanExeDotEnv`.
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.credential_read · CWE-94, CWE-1427
mcp_cloud/AGENTS.md:30
| `dotenv_utils.py` | Load `.env` from mcp_cloud/ or repo root | `load_planexe_dotenv` |
Why it matters. asks the agent to read credentials
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docker-compose.md:132
- Env defaults: derives `SQLALCHEMY_DATABASE_URI` from `PLANEXE_POSTGRES_HOST|PORT|DB|USER|PASSWORD` (fallbacks to `database_postgres` + `planexe/planexe` on 5432); `PLANEXE_CONFIG_PATH=/app`; `PLANEX
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/mcp/claude.md:13
<iframe width="560" height="315" src="https://www.youtube.com/embed/dhrgwW-8rl4?si=Hkc_e5onS6xD1Aca" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encry
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/mcp/cursor.md:23
<iframe width="560" height="315" src="https://www.youtube.com/embed/rVsH_iUZayA?si=VJz4uYnxyob4zYp_" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encry
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/proposals/52-mcp-oauth.md:65
| Token endpoint | `POST /oauth/token` – exchange `code` for access token (JWT) | Medium |
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/stripe.md:23
When the app runs on `localhost` (e.g. `http://localhost:5001`), Stripe’s servers cannot reach your machine. They need to POST to your webhook URL; `localhost` is only reachable from your own computer
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
mcp_cloud/server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha 1857824dd70afull audit observations/trust-audit/mcp-server/planexeorg__planexe.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-011857824dd70aBLOCKD63first audit
05

Questions

What is the PlanExe MCP server?

Create a plan from a description in minutes

Is PlanExe safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (63/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does PlanExe need?

It reads ANTHROPIC_API_KEY, ANTHROPIC_OAUTHTOKEN, OPENROUTER_API_KEY, PLANEXE_API_KEY_SECRET, PLANEXE_API_KEY_SHOW_ONCE, PLANEXE_AUTH_REQUIRED, PLANEXE_DATABASE_WORKER_API_KEY, PLANEXE_DOWNLOAD_TOKEN_TTL, PLANEXE_FRONTEND_MULTIUSER_SECRET_KEY, PLANEXE_MCP_API_KEY, PLANEXE_MCP_REQUIRE_USER_KEY and PLANEXE_OAUTH_DISCORD_CLIENT_ID from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does PlanExe run?

It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as PlanExe.

How current is this page?

The grade is for one exact copy of the source (1857824dd70a), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement