Atlas / MCP servers / spranab / Saga

SagaCAUTION

mcp/spranab/saga

Your agent loses the plan between sessions, so saga-mcp gives it a SQLite-backed tracker for projects, epics, tasks, subtasks, dependencies, and notes: 41 MCP tools, an activity log, and a one-call dashboard, with no accounts and no external services.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
42 18r · 18w · 6d
Transport
stdio
License
MIT
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/saga-mcp) [](https://www.npmjs.com/package/saga-mcp) [](https://github.com/spranab/saga-mcp/blob/master/LICENSE) [](https://ideacred.com/profile/spranab)

Your coding agent loses the plan between sessions. You come back tomorrow and it has no idea which of the five things you agreed on are done, which one is blocked on which, or why you rejected the second approach — because the plan lived in the context window, or in a TODO.md nobody updates.

saga-mcp gives the agent a real tracker instead: a SQLite file in your project holding projects, epics, tasks, subtasks, dependencies, comments, notes and decisions, exposed as 41 MCP tools. The agent writes to it as it works and reads it back when it returns. No accounts, no external service, no network calls — the database is a file you own.

Install

Add saga-mcp to your MCP client. The same block works for Claude Code (.mcp.json in your project), Claude Desktop (claude_desktop_config.json), and any other MCP client:

{
"mcpServers": {
"saga": {
"command": "npx",
"args": ["-y", "saga-mcp"],
"env": { "DB_PATH": "/absolute/path/to/your/project/.tracker.db" }
}
}
}

Restart the client. DB_PATH is the only required setting; the file and its schema are created on first use. Prefer a global install? npm install -g saga-mcp, then use saga-mcp as the command instead of npx.

Tested on Node 20, 22 and 24, on Linux, macOS and Windows.

Settings

Read from source at commit 79663f03215dOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code (npm)
claude mcp add saga-mcp -- npx -y [email protected]
03

Exposed tools (42)

18 read · 18 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
PaymentsreadBilling and reconciliation.
activity_logreadView the activity log showing what changed and when. Useful for understanding recent progress or reviewing what happened since the last session.
comment_addwriteAdd a comment to a task. Comments create a chronological discussion thread — useful for leaving breadcrumbs across sessions.
comment_deletedestructiveRemove a comment (soft delete). The row is kept for the audit trail but hidden from comment_list and task_get. Use this to retract a comment that turned out to be wrong or stale. Reversible with comment_restore.
comment_listwriteList comments on a task in chronological order. Comments removed with comment_delete are hidden by default; pass include_deleted to see them with their removal reason.
comment_restorereadRestore a comment previously removed with comment_delete.
epic_archivedestructiveArchive or unarchive an epic. Archived epics and their tasks drop out of listings, the dashboard and search unless include_archived is set. For putting finished work out of sight without cancelling it; nothing is deleted.
epic_createwriteCreate an epic within a project. Epics group related tasks into a feature or workstream.
epic_listreadList epics for a project with task counts and completion stats. Filter by status, priority or branch. Archived epics are hidden unless include_archived is set.
epic_updatewriteUpdate an epic. Pass only the fields you want to change. Set status to
note_deletedestructiveDelete a note by ID.
note_listreadList notes with optional filters. Returns notes sorted by most recent first.
note_savewriteCreate or update a note: decisions, context, progress, meetings, blockers, technical detail, releases. With id, updates; without, creates.
note_searchreadSearch across note titles and content by keyword.
project_createwriteCreate a new project. Projects are the top-level container for all work.
project_listreadList all projects with epic/task counts and completion percentages. Optionally filter by status.
project_updatewriteUpdate a project. Pass only the fields you want to change. Set status to
subtask_createwriteCreate subtasks (checklist items) for a task. Pass titles as an array — one string per subtask — and each becomes its own record. New subtasks are appended after any that exist.
subtask_deletedestructiveDelete one or more subtasks. Accepts a single ID or array of IDs.
subtask_reorderwriteReorder a task subtask list. Pass IDs in the order you want; any omitted keep their relative order at the end.
subtask_updatewriteUpdate a subtask title, status or position. depends_on sets what it waits on, blocks the inverse; both replace the set, [] clears. Starting or finishing one with unmet prerequisites needs force.
task_batch_updatewriteUpdate multiple tasks at once. Useful for changing status of several tasks (e.g., mark 3 tasks as done) or reassigning tasks.
task_createwriteCreate a task within an epic. Tasks are the primary unit of work.
task_deletedestructiveRemove a task (soft delete). Only
task_getreadGet a single task with full details including all subtasks, related notes, comments, and dependencies.
task_listreadList tasks; without epic_id, across all epics. Includes subtask and dependency counts.
task_lock_descriptionreadLock or unlock a task
task_reorderwriteSet the order of an epic
task_restorereadRestore a task removed with task_delete.
task_updatewriteUpdate a task; pass only fields to change. Completing it while subtasks are unfinished is refused unless force is set.
template_applywriteApply a template to create tasks in an epic. Replaces {variable} placeholders with provided values.
template_createwriteCreate a reusable set of tasks that can be instantiated into any epic. {variable} placeholders are filled in on apply.
template_deletedestructiveDelete a task template.
template_listreadList task templates. Pass include_tasks to see what each one actually creates.
template_updatewriteEdit a template in place. Only the fields you pass change; tasks replace the whole list.
tracker_dashboardreadFull project overview in one call: project, epics with task counts, stats, blocked and overdue tasks, recent activity and notes. Best first call when starting work. branch=
tracker_exportreadExport a full project as nested JSON. Includes all epics, tasks, subtasks, comments, dependencies, and related notes. Useful for backup, migration, or sharing.
tracker_importwriteImport a project from JSON (matching tracker_export format). Creates all entities with new IDs and remaps references. Uses a transaction for atomicity.
tracker_initreadInitialize the tracker for a project. If the database is empty, creates a project with the given name. If a project already exists, returns its info.
tracker_nextreadWhat to work on next: one recommended task with the reason, its next unfinished subtask, alternatives, and — when nothing is actionable — what to unblock. Call it when resuming work; cheaper than tracker_dashboard.
tracker_searchreadSearch projects, epics, tasks and notes by keyword. Returns categorized previews — use task_get or note_list for full text.
tracker_session_diffreadWhat changed since a timestamp: counts by action and entity, plus the notable changes. Call it at the start of a session to catch up.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (8 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/mcp-demo.mjs:213
const list = await (await fetch(`http://127.0.0.1:${DEBUG_PORT}/json/list`)).json();
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/screenshots.mjs:73
const list = await (await fetch(`http://127.0.0.1:${DEBUG_PORT}/json/list`)).json();
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/screenshots.mjs:139
await send('Page.navigate', { url: `http://127.0.0.1:${PORT}/${hash || ''}` });
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
comment_delete, epic_archive, note_delete, subtask_delete, task_delete, template_delete
Why it matters. 6 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, better-sqlite3, @types/better-sqlite3, @types/node, typescript
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 79663f03215dfull audit observations/trust-audit/mcp-server/spranab__saga.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0879663f03215dCAUTIONB89first audit
06

Questions

What is the Saga MCP server?

Your agent loses the plan between sessions, so saga-mcp gives it a SQLite-backed tracker for projects, epics, tasks, subtasks, dependencies, and notes: 41 MCP tools, an activity log, and a one-call dashboard, with no accounts and no external services.

What tools does Saga expose?

42 in total: 18 read-only, 18 that write, and 6 that can delete or overwrite (comment_delete, epic_archive, note_delete, subtask_delete, task_delete). Every one is listed on this page with its risk.

Is Saga safe to connect to an agent?

With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Saga need?

No credential environment variables were found in its source, so it appears to need none.

How does Saga run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as saga-mcp at 1.19.0.

How current is this page?

The grade is for one exact copy of the source (79663f03215d), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement