SagaCAUTION
Your agent loses the plan between sessions, so saga-mcp gives it a SQLite-backed tracker for projects, epics, tasks, subtasks, dependencies, and notes: 41 MCP tools, an activity log, and a one-call dashboard, with no accounts and no external services.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/saga-mcp) [](https://www.npmjs.com/package/saga-mcp) [](https://github.com/spranab/saga-mcp/blob/master/LICENSE) [](https://ideacred.com/profile/spranab)
Your coding agent loses the plan between sessions. You come back tomorrow and it has no idea which of the five things you agreed on are done, which one is blocked on which, or why you rejected the second approach — because the plan lived in the context window, or in a TODO.md nobody updates.
saga-mcp gives the agent a real tracker instead: a SQLite file in your project holding projects, epics, tasks, subtasks, dependencies, comments, notes and decisions, exposed as 41 MCP tools. The agent writes to it as it works and reads it back when it returns. No accounts, no external service, no network calls — the database is a file you own.
Install
Add saga-mcp to your MCP client. The same block works for Claude Code (.mcp.json in your project), Claude Desktop (claude_desktop_config.json), and any other MCP client:
{
"mcpServers": {
"saga": {
"command": "npx",
"args": ["-y", "saga-mcp"],
"env": { "DB_PATH": "/absolute/path/to/your/project/.tracker.db" }
}
}
}Restart the client. DB_PATH is the only required setting; the file and its schema are created on first use. Prefer a global install? npm install -g saga-mcp, then use saga-mcp as the command instead of npx.
Tested on Node 20, 22 and 24, on Linux, macOS and Windows.
Settings
79663f03215dOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add saga-mcp -- npx -y [email protected]
Exposed tools (42)
18 read · 18 write · 6 destructive. Blast radius: 6 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Payments | read | Billing and reconciliation. |
activity_log | read | View the activity log showing what changed and when. Useful for understanding recent progress or reviewing what happened since the last session. |
comment_add | write | Add a comment to a task. Comments create a chronological discussion thread — useful for leaving breadcrumbs across sessions. |
comment_delete | destructive | Remove a comment (soft delete). The row is kept for the audit trail but hidden from comment_list and task_get. Use this to retract a comment that turned out to be wrong or stale. Reversible with comment_restore. |
comment_list | write | List comments on a task in chronological order. Comments removed with comment_delete are hidden by default; pass include_deleted to see them with their removal reason. |
comment_restore | read | Restore a comment previously removed with comment_delete. |
epic_archive | destructive | Archive or unarchive an epic. Archived epics and their tasks drop out of listings, the dashboard and search unless include_archived is set. For putting finished work out of sight without cancelling it; nothing is deleted. |
epic_create | write | Create an epic within a project. Epics group related tasks into a feature or workstream. |
epic_list | read | List epics for a project with task counts and completion stats. Filter by status, priority or branch. Archived epics are hidden unless include_archived is set. |
epic_update | write | Update an epic. Pass only the fields you want to change. Set status to |
note_delete | destructive | Delete a note by ID. |
note_list | read | List notes with optional filters. Returns notes sorted by most recent first. |
note_save | write | Create or update a note: decisions, context, progress, meetings, blockers, technical detail, releases. With id, updates; without, creates. |
note_search | read | Search across note titles and content by keyword. |
project_create | write | Create a new project. Projects are the top-level container for all work. |
project_list | read | List all projects with epic/task counts and completion percentages. Optionally filter by status. |
project_update | write | Update a project. Pass only the fields you want to change. Set status to |
subtask_create | write | Create subtasks (checklist items) for a task. Pass titles as an array — one string per subtask — and each becomes its own record. New subtasks are appended after any that exist. |
subtask_delete | destructive | Delete one or more subtasks. Accepts a single ID or array of IDs. |
subtask_reorder | write | Reorder a task subtask list. Pass IDs in the order you want; any omitted keep their relative order at the end. |
subtask_update | write | Update a subtask title, status or position. depends_on sets what it waits on, blocks the inverse; both replace the set, [] clears. Starting or finishing one with unmet prerequisites needs force. |
task_batch_update | write | Update multiple tasks at once. Useful for changing status of several tasks (e.g., mark 3 tasks as done) or reassigning tasks. |
task_create | write | Create a task within an epic. Tasks are the primary unit of work. |
task_delete | destructive | Remove a task (soft delete). Only |
task_get | read | Get a single task with full details including all subtasks, related notes, comments, and dependencies. |
task_list | read | List tasks; without epic_id, across all epics. Includes subtask and dependency counts. |
task_lock_description | read | Lock or unlock a task |
task_reorder | write | Set the order of an epic |
task_restore | read | Restore a task removed with task_delete. |
task_update | write | Update a task; pass only fields to change. Completing it while subtasks are unfinished is refused unless force is set. |
template_apply | write | Apply a template to create tasks in an epic. Replaces {variable} placeholders with provided values. |
template_create | write | Create a reusable set of tasks that can be instantiated into any epic. {variable} placeholders are filled in on apply. |
template_delete | destructive | Delete a task template. |
template_list | read | List task templates. Pass include_tasks to see what each one actually creates. |
template_update | write | Edit a template in place. Only the fields you pass change; tasks replace the whole list. |
tracker_dashboard | read | Full project overview in one call: project, epics with task counts, stats, blocked and overdue tasks, recent activity and notes. Best first call when starting work. branch= |
tracker_export | read | Export a full project as nested JSON. Includes all epics, tasks, subtasks, comments, dependencies, and related notes. Useful for backup, migration, or sharing. |
tracker_import | write | Import a project from JSON (matching tracker_export format). Creates all entities with new IDs and remaps references. Uses a transaction for atomicity. |
tracker_init | read | Initialize the tracker for a project. If the database is empty, creates a project with the given name. If a project already exists, returns its info. |
tracker_next | read | What to work on next: one recommended task with the reason, its next unfinished subtask, alternatives, and — when nothing is actionable — what to unblock. Call it when resuming work; cheaper than tracker_dashboard. |
tracker_search | read | Search projects, epics, tasks and notes by keyword. Returns categorized previews — use task_get or note_list for full text. |
tracker_session_diff | read | What changed since a timestamp: counts by action and entity, plus the notable changes. Call it at the start of a session to catch up. |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
const list = await (await fetch(`http://127.0.0.1:${DEBUG_PORT}/json/list`)).json();const list = await (await fetch(`http://127.0.0.1:${DEBUG_PORT}/json/list`)).json();await send('Page.navigate', { url: `http://127.0.0.1:${PORT}/${hash || ''}` });comment_delete, epic_archive, note_delete, subtask_delete, task_delete, template_delete
@modelcontextprotocol/sdk, better-sqlite3, @types/better-sqlite3, @types/node, typescript
Gates applied: no_behavioural_pass.
79663f03215dfull audit observations/trust-audit/mcp-server/spranab__saga.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 79663f03215d | CAUTION | B | 89 | first audit |
Questions
What is the Saga MCP server?
Your agent loses the plan between sessions, so saga-mcp gives it a SQLite-backed tracker for projects, epics, tasks, subtasks, dependencies, and notes: 41 MCP tools, an activity log, and a one-call dashboard, with no accounts and no external services.
What tools does Saga expose?
42 in total: 18 read-only, 18 that write, and 6 that can delete or overwrite (comment_delete, epic_archive, note_delete, subtask_delete, task_delete). Every one is listed on this page with its risk.
Is Saga safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 6 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Saga need?
No credential environment variables were found in its source, so it appears to need none.
How does Saga run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as saga-mcp at 1.19.0.
How current is this page?
The grade is for one exact copy of the source (79663f03215d), read on 2026-10-08. The repository is watched and re-audited when it changes.