Plan CascadeBLOCK
AI-powered cascading development framework. Decompose complex projects into parallel executable tasks with auto-generated PRDs, design docs, and multi-agent collaboration (Claude Code, Codex, Aider).
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
AI-Powered Cascading Development Framework
Transform complex projects into parallel executable tasks with intelligent decomposition and multi-provider execution
[](https://opensource.org/licenses/MIT)
Why Plan Cascade? • Product Editions • Quick Start • Architecture
Why Plan Cascade?
Traditional AI coding assistants hit a wall with large, complex projects:
The Solution: Cascading Decomposition
┌───────────────────────────────────────
30812261d5e4OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add plan-cascade-desktop --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env DASHSCOPE_API_KEY=${DASHSCOPE_API_KEY} --env DEEPSEEK_API_KEY=${DEEPSEEK_API_KEY} --env GLM_API_KEY=${GLM_API_KEY} -- npx -y [email protected]{
"mcpServers": {
"plan-cascade-desktop": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
"DASHSCOPE_API_KEY": "${DASHSCOPE_API_KEY}",
"DEEPSEEK_API_KEY": "${DEEPSEEK_API_KEY}",
"GLM_API_KEY": "${GLM_API_KEY}"
}
}
}
}Exposed tools (55)
38 read · 15 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
Basic | read | A simple project overview template |
Troubleshooting | read | Template for common issues and solutions |
append_findings | read | |
check_agents | read | |
cleanup_locks | read | |
dashboard | read | |
design_generate | read | |
design_get | read | |
design_import | write | |
design_review | read | |
edit_file | write | Edit a file by replacing a specific string with new content. |
execute_story_with_agent | write | |
get_agent_output | read | |
get_agent_result | read | |
get_agent_status | read | |
get_available_agents | read | |
get_configuration | read | |
get_execution_status | read | |
get_progress | read | |
get_story_context | read | |
grep_content | read | Search for content matching a regex pattern in files. |
list_files | read | List files in current directory |
mark_story_complete | read | |
mega_add_feature | write | |
mega_generate | read | |
mega_get_batches | read | |
mega_get_merge_plan | write | |
mega_update_feature_status | write | |
mega_validate | read | |
my_tool | read | Does something |
new-name | read | new desc |
prd_add_story | write | |
prd_detect_dependencies | read | |
prd_generate | read | |
prd_get_batches | read | |
prd_update_story_status | write | |
prd_validate | read | |
read_file | read | Read the contents of a file. Returns the file content with line numbers. |
run_command | write | Execute a shell command. Returns stdout and stderr. |
search_files | read | Search for files matching a glob pattern. |
session_recover | read | |
set_default_agent | write | |
spec_cleanup | read | |
spec_get_status | read | |
spec_resume | read | |
spec_start | write | |
spec_submit_answers | write | |
stop_agent | write | |
update_configuration | write | |
wait_for_agent | read | |
worktree_complete | read | |
worktree_create | write | |
worktree_list | read | |
worktree_remove | destructive | |
write_file | destructive | Create a new file or completely overwrite an existing file with new content. |
Trust audit
BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (14 observation(s))
- Network
- declared (16 observation(s))
- Shell
- declared (7 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
let content = "Token: ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij";
let content = "Slack: xoxb-123456-abcdef-ghijkl";
description: "Dangerous eval() function usage".to_string(),
description: "Dangerous exec() function usage".to_string(),
exec(code, merge_coordinator.__dict__)
assert!(validate_url_ssrf("https://169.254.169.254").await.is_err());# Add to PATH for current session
icon.icns
assert_eq!(cfg.url(), "http://127.0.0.1:8080");
base_url: Some("http://192.168.1.100:11434".to_string()),assert_eq!(provider.base_url(), "http://192.168.1.100:11434");
validate_channel_target(&WebhookChannelType::Custom, "http://127.0.0.1:8080/hook")
.send_task("http://192.0.2.1:1/nonexistent", request)//! Prompt-Based Tool Calling Fallback
-e SLACK_MCP_XOXB_TOKEN=xoxb-your-bot-token \
-e SLACK_MCP_XOXB_TOKEN=xoxb-your-bot-token \
SLACK_MCP_XOXB_TOKEN=xoxb-your-bot-token
curl -LsSf https://astral.sh/uv/install.sh | sh
worktree_remove, write_file
.gitmodules
.prettierignore
.prettierrc.json
staged_hash = hashlib.md5(staged_diff.encode()).hexdigest()[:8] if exit_code == 0 else "none"
unstaged_hash = hashlib.md5(unstaged_diff.encode()).hexdigest()[:8] if exit_code == 0 else "none"
return hashlib.md5(combined.encode()).hexdigest()
Gates applied: critical_finding, no_behavioural_pass.
30812261d5e4full audit observations/trust-audit/mcp-server/taoidle__plan-cascade.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 30812261d5e4 | BLOCK | F | 43 | first audit |
Questions
What is the Plan Cascade MCP server?
AI-powered cascading development framework. Decompose complex projects into parallel executable tasks with auto-generated PRDs, design docs, and multi-agent collaboration (Claude Code, Codex, Aider).
What tools does Plan Cascade expose?
55 in total: 38 read-only, 15 that write, and 2 that can delete or overwrite (worktree_remove, write_file). Every one is listed on this page with its risk.
Is Plan Cascade safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (43/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Plan Cascade need?
It reads ANTHROPIC_API_KEY, DASHSCOPE_API_KEY, DEEPSEEK_API_KEY, GLM_API_KEY, NOVITA_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Plan Cascade run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as plan-cascade-desktop at 0.1.0.
How current is this page?
The grade is for one exact copy of the source (30812261d5e4), read on 2026-10-07. The repository is watched and re-audited when it changes.