AsanaCAUTION
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/@roychri/mcp-server-asana)
This Model Context Protocol server implementation of Asana allows you to talk to Asana API from MCP Client such as Anthropic's Claude Desktop Application, and many more.
More details on MCP here:
- https://www.anthropic.com/news/model-context-protocol
- https://modelcontextprotocol.io/introduction
- https://github.com/modelcontextprotocol
Environment Variables
ASANA_ACCESS_TOKEN: (Required) Your Asana access tokenREAD_ONLY_MODE: (Optional) Set to 'true' to disable all write operations. In this mode:- Tools that modify Asana data (create, update, delete) will be disabled
- The
create-taskprompt will be disabled - Only read operations will be available
This is useful for testing or when you want to ensure no changes can be made to your Asana workspace.
Usage
In the AI tool of your choice (ex: Claude Desktop) ask something about asana tasks, projects, workspaces, and/or comments. Mentioning the word "asana" will increase the chance of having the LLM pick the right tool.
Example:
How many unfinished asana tasks do we have in our Sprint 30 project?
Another example:
Tools
asana_list_workspaces- List all available workspaces in Asana
- Optional input:
- opt_fields (string): Comma-separated list of optional fields to include
- Returns: List of workspaces
asana_search_projects- Search for projects in Asana using name pattern matching
- Required input:
- workspace (string): The workspace to search in
- name_pattern (string):
80d87654986bOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-server-asana --env ASANA_ACCESS_TOKEN=${ASANA_ACCESS_TOKEN} -- npx -y @roychri/[email protected]{
"mcpServers": {
"mcp-server-asana": {
"command": "npx",
"args": [
"-y",
"@roychri/[email protected]"
],
"env": {
"ASANA_ACCESS_TOKEN": "${ASANA_ACCESS_TOKEN}"
}
}
}
}Exposed tools (49)
23 read · 20 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
asana_add_project_to_task | write | Add an existing task to a project. If no positioning arguments are given, the task will be added to the end of the project. |
asana_add_tag_to_task | write | Add a tag to a task |
asana_add_task_dependencies | write | Set dependencies for a task |
asana_add_task_dependents | write | Set dependents for a task (tasks that depend on this task) |
asana_add_task_to_section | write | Move a task to a section within its project |
asana_create_project | write | Create a new project in a workspace or team |
asana_create_project_status | write | Create a new status update for a project |
asana_create_section | write | Create a new section in a project |
asana_create_subtask | write | Create a new subtask for an existing task |
asana_create_tag_for_workspace | write | Create a new tag in a workspace |
asana_create_task | write | Create a new task in a project |
asana_create_task_story | write | Create a comment or story on a task. Either text or html_text is required. |
asana_delete_project_status | destructive | Delete a project status update |
asana_delete_section | destructive | Delete a section from a project |
asana_delete_tag | destructive | Delete a tag |
asana_delete_task | destructive | Delete a task. This permanently removes the task and cannot be undone. |
asana_get_multiple_tasks_by_gid | read | Get detailed information about multiple tasks by their GIDs (maximum 25 tasks) |
asana_get_my_tasks | read | Get tasks from the authenticated user |
asana_get_project | read | Get detailed information about a specific project |
asana_get_project_sections | read | Get sections in a project |
asana_get_project_status | write | Get a project status update |
asana_get_project_statuses | read | Get all status updates for a project |
asana_get_project_task_counts | read | Get the number of tasks in a project |
asana_get_subtasks | read | Get all subtasks of a given task. Returns a compact representation of each subtask. |
asana_get_tag | read | Get detailed information about a specific tag |
asana_get_tags_for_task | read | Get a task |
asana_get_tags_for_workspace | read | Get tags in a workspace |
asana_get_task | read | Get detailed information about a specific task |
asana_get_task_stories | read | Get comments and stories for a specific task |
asana_get_tasks_for_project | read | Get all tasks in a project. Use this instead of search_tasks when you need to list tasks in a specific project. Supports pagination and optional field selection. |
asana_get_tasks_for_tag | read | Get tasks for a specific tag |
asana_list_workspaces | read | List all available workspaces in Asana |
asana_remove_project_from_task | destructive | Remove a task from a project. The task will still exist in the system, but it will not be in the project anymore. |
asana_remove_tag_from_task | destructive | Remove a tag from a task |
asana_search_projects | read | Search for projects in Asana using name pattern matching |
asana_search_tasks | read | Search tasks in a workspace with advanced filtering options |
asana_set_parent_for_task | write | Set the parent of a task and position the subtask within the other subtasks of that parent |
asana_update_project | write | Update a project |
asana_update_section | write | Update a section (rename it) |
asana_update_tag | write | Update an existing tag |
asana_update_task | write | Update an existing task |
create-task | write | Create a new task with specified details |
due_date | read | Due date for the task (YYYY-MM-DD format) |
notes | read | Notes or description for the task |
project_name | read | The name of the Asana project where the task should be created |
task-completeness | read | Analyze if a task description contains all necessary details for completion |
task-summary | write | Get a summary and status update for a task based on its notes, custom fields and comments |
task_id | read | The task ID to get summary for |
title | read | The title of the task |
Trust audit
CAUTIONgrade B · trust 88/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (4)
All information in this guide comes from official Anthropic documentation and verified community resources.
asana_delete_project_status, asana_delete_section, asana_delete_tag, asana_delete_task, asana_remove_project_from_task, asana_remove_tag_from_task
.aider.conf.yml
@modelcontextprotocol/sdk, asana, jsdom, @modelcontextprotocol/inspector, @tsconfig/node20, @types/jsdom, @types/node, esbuild
Gates applied: no_behavioural_pass.
80d87654986bfull audit observations/trust-audit/mcp-server/roychri__asana.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 80d87654986b | CAUTION | B | 88 | first audit |
Questions
What tools does Asana expose?
49 in total: 23 read-only, 20 that write, and 6 that can delete or overwrite (asana_delete_project_status, asana_delete_section, asana_delete_tag, asana_delete_task, asana_remove_project_from_task). Every one is listed on this page with its risk.
Is Asana safe to connect to an agent?
With care. The audit graded it B (88/100) and found 4 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Asana need?
It reads ASANA_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Asana run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @roychri/mcp-server-asana at 1.8.0.
How current is this page?
The grade is for one exact copy of the source (80d87654986b), read on 2026-10-07. The repository is watched and re-audited when it changes.