Atlas / MCP servers / prat011 / Monday.com

Monday.comSAFE

mcp/prat011/monday-com-1

MCP Server to interact with Monday.com boards and items

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
15 8r · 6w · 1d
Transport
—
License
MIT
Stars
34
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

MCP Server for monday.com, enabling MCP clients to interact with Monday.com boards, items, updates, and documents.

Components

Tools

The server implements the following tools:

  • monday-create-item: Creates a new item or sub-item in a Monday.com board
  • monday-get-board-groups: Retrieves all groups from a specified Monday.com board
  • monday-create-update: Creates a comment/update on a Monday.com item
  • monday-list-boards: Lists all available Monday.com boards
  • monday-list-items-in-groups: Lists all items in specified groups of a Monday.com board
  • monday-list-subitems-in-items: Lists all sub-items for given Monday.com items
  • monday-create-board: Creates a new Monday.com board
  • monday-create-board-group: Creates a new group in a Monday.com board
  • monday-move-item-to-group: Moves a Monday.com item to a different group
  • monday-delete-item: Deletes a Monday.com item
  • monday-archive-item: Archives a Monday.com item
  • monday-get-item-updates: Retrieves updates/comments for a specific item
  • monday-get-docs: Lists documents in Monday.com, optionally filtered by folder
  • monday-get-doc-content: Retrieves the content of a specific document
  • monday-create-doc: Creates a new document in Monday.com
  • monday-add-doc-block: Adds a block to an existing document

Setup

  1. Create and save a personal API Token in Monday.com by following the instructions here.
  2. Get the Workspace Name from the URL of your Monday.com workspace. For example, if the URL is https://myworkspace.monday.com/, the workspace name is myworkspace.

Quickstart

Using Rube

  1. Go to (Rube.app)[https://rube.app/]
  2. Install Rube in your preferred client including Cursor, Claude, VS Code, Windsurf etc.,
  3. Complete authentication with Rube
  4. You can now execute actions on Monday.com like creating items, posting upda
Read from source at commit 6201533dbe85OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-server-monday --env MONDAY_API_KEY=${MONDAY_API_KEY} -- uvx mcp-server-monday
claude-desktop
{
  "mcpServers": {
    "mcp-server-monday": {
      "command": "uvx",
      "args": [
        "mcp-server-monday"
      ],
      "env": {
        "MONDAY_API_KEY": "${MONDAY_API_KEY}"
      }
    }
  }
}
03

Exposed tools (15)

8 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
monday_archive_itemreadArchive an item from a Monday.com board.
monday_create_boardwriteCreate a new Monday.com board.
monday_create_board_groupwriteCreate a new group in a Monday.com board.
monday_create_itemwriteCreate a new item in a Monday.com Board. Optionally, specify the parent Item ID to create a Sub-item.
monday_create_updatewriteCreate an update (comment) on a Monday.com Item or Sub-item.
monday_delete_itemdestructiveDelete an item from a Monday.com board.
monday_get_board_columnsreadGet the Columns of a Monday.com Board.
monday_get_board_groupsreadGet the Groups of a Monday.com Board.
monday_get_item_updatesreadGet updates for a specific item in Monday.com.
monday_get_items_by_idreadFetch specific Monday.com item by its ID.
monday_list_boardsreadGet all Boards from Monday.com.
monday_list_items_in_groupsreadList all items in the specified groups of a Monday.com board.
monday_list_subitems_in_itemsreadList all Sub-items of a list of Monday.com Items.
monday_move_item_to_groupwriteMove an item to a group in a Monday.com board.
monday_update_itemwriteUpdate a Monday.com item
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
monday_delete_item
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 6201533dbe85full audit observations/trust-audit/mcp-server/prat011__monday-com-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-086201533dbe85SAFEB89first audit
06

Questions

What is the Monday.com MCP server?

MCP Server to interact with Monday.com boards and items

What tools does Monday.com expose?

15 in total: 8 read-only, 6 that write, and 1 that can delete or overwrite (monday_delete_item). Every one is listed on this page with its risk.

Is Monday.com safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Monday.com need?

It reads MONDAY_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (6201533dbe85), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement