Atlas / MCP servers / talhaorak / Pytaiga

PytaigaSAFE

mcp/talhaorak/pytaiga

A MCP server for interacting with Taiga Project Manager

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
94 62r · 22w · 10d
Transport
—
License
MIT
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.python.org/downloads/) [](https://ghcr.io/tetra-2023/pytaiga-mcp) [](https://opensource.org/licenses/MIT)

Community fork of talhaorak/pytaiga-mcp with additional features, CI/CD, and ongoing maintenance.

Overview

The Taiga MCP Bridge is a powerful integration layer that connects Taiga project management platform with the Model Context Protocol (MCP), enabling AI tools and workflows to interact seamlessly with Taiga's resources.

This bridge provides a comprehensive set of tools and resources for AI agents to:

  • Create and manage projects, epics, user stories, tasks, and issues in Taiga
  • Track sprints and milestones
  • Assign and update work items
  • Query detailed information about project artifacts
  • Manage project members and permissions

By using the MCP standard, this bridge allows AI systems to maintain contextual awareness about project state and perform complex project management tasks programmatically.

Features

Comprehensive Resource Support

The bridge supports the following Taiga resources with complete CRUD operations:

  • Projects: Create, update, and manage project settings and metadata
  • Epics: Manage large features that span multiple sprints
  • User Stories: Handle detailed requirements and acceptance criteria
  • Tasks: Track smaller units of work within user stories
  • Issues: Manage bugs, questions, and enhancement requests
  • Sprints (Milestones): Plan and track work in time-boxed intervals

Security & Configuration

  • Secure Credentials: Environment variable authentication w
Read from source at commit effa04451a96OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-taiga-bridge --env TAIGA_PASSWORD=${TAIGA_PASSWORD} --env TAIGA_TEST_PASSWORD=${TAIGA_TEST_PASSWORD} -- uvx mcp-taiga-bridge
claude-desktop
{
  "mcpServers": {
    "mcp-taiga-bridge": {
      "command": "uvx",
      "args": [
        "mcp-taiga-bridge"
      ],
      "env": {
        "TAIGA_PASSWORD": "${TAIGA_PASSWORD}",
        "TAIGA_TEST_PASSWORD": "${TAIGA_TEST_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (94)

62 read · 22 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_commentwriteAdd a comment to a Taiga object (issue, task, user_story, or epic).
assign_epic_to_userread
assign_issue_to_userread
assign_task_to_userread
assign_user_story_to_userread
bulk_create_epicswrite
bulk_create_taskswrite
bulk_create_user_storieswrite
bulk_update_story_sprintwrite
create_epicwrite
create_issuewrite
create_milestonewrite
create_projectwrite
create_project_tagwrite
create_taskwrite
create_user_storywrite
create_wiki_linkwrite
create_wiki_pagewrite
delete_attachmentdestructive
delete_epicdestructive
delete_issuedestructive
delete_milestonedestructive
delete_projectdestructive
delete_project_tagdestructive
delete_taskdestructive
delete_user_storydestructive
delete_wiki_linkdestructive
delete_wiki_pagedestructive
downvote_itemread
get_custom_attribute_valuesread
get_default_sessionread
get_epicread
get_epic_by_refread
get_filters_dataread
get_historyread
get_issueread
get_issue_by_refread
get_issue_prioritiesread
get_issue_severitiesread
get_issue_statusesread
get_issue_typesread
get_milestoneread
get_milestone_statsread
get_projectread
get_project_by_slugread
get_project_issue_statsread
get_project_membersread
get_project_statsread
get_project_tagsread
get_project_timelineread
get_taskread
get_task_by_refread
get_task_statusesread
get_user_storyread
get_user_story_by_refread
get_user_story_statusesread
get_user_timelineread
get_wiki_pageread
invite_project_userread
link_user_story_to_epicread
list_all_projectsread
list_attachmentsread
list_commentsreadList comments on a Taiga object (issue, task, user_story, or epic).
list_custom_attributesread
list_epicsread
list_issuesread
list_milestonesread
list_pointsread
list_projectsread
list_rolesread
list_tasksread
list_user_storiesread
list_wiki_linksread
list_wiki_pagesread
loginread
logoutread
resolveread
searchread
session_statusread
set_custom_attribute_valueswrite
unassign_epic_from_userread
unassign_issue_from_userread
unassign_task_from_userread
unassign_user_story_from_userread
unwatch_itemread
update_epicwrite
update_issuewrite
update_milestonewrite
update_projectwrite
update_taskwrite
update_user_storywrite
update_wiki_pagewrite
upvote_itemread
watch_itemread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_attachment, delete_epic, delete_issue, delete_milestone, delete_project, delete_project_tag, delete_task, delete_user_story, delete_wiki_link, delete_wiki_page
Why it matters. 10 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
MCP_SDK.md:414
For more control, you can use the low-level server implementation directly. This gives you full access to the protocol and allows you to customize every aspect of your server, including lifecycle mana
LOWPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
SECURITY.md:23
- **API Access**: This bridge has full access to your Taiga instance based on the authenticated user's permissions

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha effa04451a96full audit observations/trust-audit/mcp-server/talhaorak__pytaiga.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08effa04451a96SAFEB89first audit
06

Questions

What is the Pytaiga MCP server?

A MCP server for interacting with Taiga Project Manager

What tools does Pytaiga expose?

94 in total: 62 read-only, 22 that write, and 10 that can delete or overwrite (delete_attachment, delete_epic, delete_issue, delete_milestone, delete_project). Every one is listed on this page with its risk.

Is Pytaiga safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Pytaiga need?

It reads TAIGA_PASSWORD and TAIGA_TEST_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (effa04451a96), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement