Carrot AI PMBLOCK
Carrot auto-writes specs and catches AI code drift. MCP server for Cursor that AST-validates every commit.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://opensource.org/licenses/MIT) [](CONTRIBUTING.md) [](https://modelcontextprotocol.io)
Carrot generates specs, validates output, and keeps AI assistants aligned. ----
Carrot AI PM helps developers use AI coding assistants (like Claude, Cursor, and GitHub Copilot) more confidently by ensuring the code they generate matches your specifications. Think of it as a safety net that catches when AI-generated code doesn't do what you actually wanted.
Why "Carrot"?
Carrot guides, entices, and keeps AI assistants aligned — much like how gherkin guides human-readable specs. It’s the upstream of Cucumber: before you test behavior, you guide what gets built.
Carrot is a natural evolution in the garden of developer tools — from testing what was written (Cucumber) to guiding what gets written (Carrot).
🤔 The Problem
When using AI to write code, you might ask:
- "Create a user login API"
- "Build a product card component"
- "Set up a database for my e-commerce site"
But how do you know if the AI understood correctly? How can you be sure the generated code:
- Has proper error handling?
- Includes all the features you need?
- Follows security best practices?
- Works with your existing code?
💡 How Carrot AI PM Helps
Carrot AI PM acts as your AI coding assistant's "project manager". It:
- Creates clear specifications before coding starts
- Checks if the code matches what was specified
- Suggests specific fixes when something's wrong
- Gives you confidence that AI-generated code is correct
🎯 Real-World Example
Instead of just asking your AI to "create a user API", you can:
- You say: "Create a specification for a user management A
88fee54646deOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add carrot-ai-pm --env GITHUB_TOKEN=${GITHUB_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"carrot-ai-pm": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"GITHUB_TOKEN": "${GITHUB_TOKEN}"
}
}
}
}Exposed tools (53)
43 read · 8 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
README.md | read | Repository documentation |
active | read | Pressed/clicked state |
add_route | write | |
check_spec_compliance | read | |
clean | read | Clean build artifacts |
commit_changes | write | |
default | read | Normal interactive state |
delete_playlist_success | destructive | Successfully delete user\ |
delete_playlist_unauthorized | destructive | Attempt to delete another user\ |
disabled | read | Non-interactive disabled state |
documentation | read | Comprehensive documentation for Carrot features and APIs |
enforce_foreign_keys | read | All foreign key constraints must be enforced |
error | read | Input has validation error |
focus | read | Keyboard focus state |
format_code | read | |
general_error | read | General error occurred |
get_playlist_not_found | read | Attempt to get non-existent playlist |
get_playlist_unauthorized | read | Attempt to access another user\ |
get_user_playlist_success | read | Successfully retrieve user\ |
grow_cli_spec | read | |
grow_db_spec | read | |
grow_spec | read | |
grow_ui_spec | read | |
hover | read | Mouse hover state |
input | read | Input file or directory |
interrupted | read | Command was interrupted by user |
invalid_request | read | Test invalid request handling |
json | read | Machine-readable JSON output |
loading | read | Processing/loading state |
multi-task-specs | read | Support for defining complex tasks with multiple subtasks and dependencies |
onBlur | read | Fired when button loses focus |
onChange | read | Fired when input value changes |
onClick | read | Fired when button is clicked |
onFocus | read | Fired when button receives focus |
production | write | Deploy to production environment |
refine-spec-tool | read | Tool for iteratively refining and updating task specifications |
run_tests | write | |
search_code | read | |
setup_carrot | read | |
source | read | Source directory to build |
staging | write | Deploy to staging environment |
success | read | Command completed successfully |
successful_request | read | Test successful request handling |
task-metadata | read | Extended metadata for task tracking, visualization, and management |
text | read | Human-readable text output |
update_playlist_invalid_data | write | Attempt to update with invalid data |
update_playlist_partial | write | Successfully update only playlist name |
update_playlist_success | write | Successfully update playlist name and description |
usage_error | read | Invalid command line usage |
user-notifications | read | System for notifying users about task status changes and events |
vibe.yaml | read | OpenAPI specification for the API |
watch | read | Watch for changes and rebuild |
yaml | read | YAML formatted output |
Trust audit
BLOCKgrade D · trust 62/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (2 observation(s))
- Network
- declared (2 observation(s))
- Shell
- declared (4 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (12)
spec = yaml.load(fs.readFileSync(vibeYamlPath, 'utf8')) as any;
return yaml.load(content);
return yaml.load(content);
return yaml.load(content);
delete_playlist_success, delete_playlist_unauthorized
existingYaml = yaml.load(fs.readFileSync(vibeYamlPath, 'utf8')) as any;
locations: ['~/.config/app', './config', '/etc/app'],
const packageJsonPath = path.join(__dirname, '../../../package.json');
import { Client } from '../../client/index.js';import { StreamableHTTPClientTransport } from '../../client/streamableHttp.js';import { ListToolsResultSchema, CallToolResultSchema, ListPromptsResultSchema, GetPromptResultSchema, ListResourcesResultSchema, LoggingMessageNotificationSchema, ResourceListChangedNotificationSchema@modelcontextprotocol/sdk, @types/express, @types/js-yaml, @types/node, @types/node-fetch, child_process, express, fs
Gates applied: no_behavioural_pass.
88fee54646defull audit observations/trust-audit/mcp-server/talvinder__carrot-ai-pm.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 88fee54646de | BLOCK | D | 62 | first audit |
Questions
What is the Carrot AI PM MCP server?
Carrot auto-writes specs and catches AI code drift. MCP server for Cursor that AST-validates every commit.
What tools does Carrot AI PM expose?
53 in total: 43 read-only, 8 that write, and 2 that can delete or overwrite (delete_playlist_success, delete_playlist_unauthorized). Every one is listed on this page with its risk.
Is Carrot AI PM safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (62/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Carrot AI PM need?
It reads GITHUB_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Carrot AI PM run?
It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as carrot-ai-pm at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (88fee54646de), read on 2026-10-08. The repository is watched and re-audited when it changes.