Atlas / MCP servers / taoidle / Plan Cascade

Plan CascadeBLOCK

mcp/taoidle/plan-cascade

AI-powered cascading development framework. Decompose complex projects into parallel executable tasks with auto-generated PRDs, design docs, and multi-agent collaboration (Claude Code, Codex, Aider).

Verdict
BLOCK
Grade
F
Trust score
43 /100
Exposed tools
55 38r · 15w · 2d
Transport
sse · stdio · streamable-http
License
MIT
Stars
133
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

AI-Powered Cascading Development Framework

Transform complex projects into parallel executable tasks with intelligent decomposition and multi-provider execution

[](https://opensource.org/licenses/MIT)

Why Plan Cascade? • Product Editions • Quick Start • Architecture

Why Plan Cascade?

Traditional AI coding assistants hit a wall with large, complex projects:

The Solution: Cascading Decomposition

┌───────────────────────────────────────
Read from source at commit 30812261d5e4OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add plan-cascade-desktop --env ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY} --env DASHSCOPE_API_KEY=${DASHSCOPE_API_KEY} --env DEEPSEEK_API_KEY=${DEEPSEEK_API_KEY} --env GLM_API_KEY=${GLM_API_KEY} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "plan-cascade-desktop": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "ANTHROPIC_API_KEY": "${ANTHROPIC_API_KEY}",
        "DASHSCOPE_API_KEY": "${DASHSCOPE_API_KEY}",
        "DEEPSEEK_API_KEY": "${DEEPSEEK_API_KEY}",
        "GLM_API_KEY": "${GLM_API_KEY}"
      }
    }
  }
}
03

Exposed tools (55)

38 read · 15 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
BasicreadA simple project overview template
TroubleshootingreadTemplate for common issues and solutions
append_findingsread
check_agentsread
cleanup_locksread
dashboardread
design_generateread
design_getread
design_importwrite
design_reviewread
edit_filewriteEdit a file by replacing a specific string with new content.
execute_story_with_agentwrite
get_agent_outputread
get_agent_resultread
get_agent_statusread
get_available_agentsread
get_configurationread
get_execution_statusread
get_progressread
get_story_contextread
grep_contentreadSearch for content matching a regex pattern in files.
list_filesreadList files in current directory
mark_story_completeread
mega_add_featurewrite
mega_generateread
mega_get_batchesread
mega_get_merge_planwrite
mega_update_feature_statuswrite
mega_validateread
my_toolreadDoes something
new-namereadnew desc
prd_add_storywrite
prd_detect_dependenciesread
prd_generateread
prd_get_batchesread
prd_update_story_statuswrite
prd_validateread
read_filereadRead the contents of a file. Returns the file content with line numbers.
run_commandwriteExecute a shell command. Returns stdout and stderr.
search_filesreadSearch for files matching a glob pattern.
session_recoverread
set_default_agentwrite
spec_cleanupread
spec_get_statusread
spec_resumeread
spec_startwrite
spec_submit_answerswrite
stop_agentwrite
update_configurationwrite
wait_for_agentread
worktree_completeread
worktree_createwrite
worktree_listread
worktree_removedestructive
write_filedestructiveCreate a new file or completely overwrite an existing file with new content.
04

Trust audit

BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (14 observation(s))
Network
declared (16 observation(s))
Shell
declared (7 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (25)

CRITICALHard-coded secrets · secret.github · CWE-798, CWE-321
desktop/src-tauri/src/services/guardrail/sensitive_data.rs:298
let content = "Token: ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghij";
CRITICALHard-coded secrets · secret.slack · CWE-798, CWE-321
desktop/src-tauri/src/services/guardrail/sensitive_data.rs:309
let content = "Slack: xoxb-123456-abcdef-ghijkl";
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
desktop/src-tauri/src/services/guardrail/code_security.rs:56
description: "Dangerous eval() function usage".to_string(),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
desktop/src-tauri/src/services/guardrail/code_security.rs:62
description: "Dangerous exec() function usage".to_string(),
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
mcp_server/tools/mega_tools.py:71
exec(code, merge_coordinator.__dict__)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHNetwork egress · net.metadata_ip · CWE-200, CWE-319
desktop/src-tauri/src/services/tools/url_validation.rs:144
assert!(validate_url_ssrf("https://169.254.169.254").await.is_err());
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
HIGHPrompt injection · prompt.persistence · CWE-94, CWE-1427
commands/init.md:39
# Add to PATH for current session
Why it matters. instructs the agent to persist itself in the user's environment
MEDIUMInventory / provenance · inv.binary · CWE-1104
desktop/src-tauri/icons/icon.icns
icon.icns
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
desktop/src-tauri/crates/core/src/proxy.rs:107
assert_eq!(cfg.url(), "http://127.0.0.1:8080");
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
desktop/src-tauri/crates/llm/src/ollama.rs:823
base_url: Some("http://192.168.1.100:11434".to_string()),
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
desktop/src-tauri/crates/llm/src/ollama.rs:827
assert_eq!(provider.base_url(), "http://192.168.1.100:11434");
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
desktop/src-tauri/src/commands/webhook.rs:849
validate_channel_target(&WebhookChannelType::Custom, "http://127.0.0.1:8080/hook")
MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
desktop/src-tauri/src/services/a2a/client.rs:324
.send_task("http://192.0.2.1:1/nonexistent", request)
MEDIUMObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
desktop/src-tauri/src/services/tools/prompt_fallback.rs:1
//! Prompt-Based Tool Calling Fallback
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/MCP-INTEGRATION-RESEARCH.md:471
-e SLACK_MCP_XOXB_TOKEN=xoxb-your-bot-token \
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/MCP-INTEGRATION-RESEARCH.md:484
-e SLACK_MCP_XOXB_TOKEN=xoxb-your-bot-token \
MEDIUMHard-coded secrets · secret.slack · CWE-798, CWE-321
docs/MCP-INTEGRATION-RESEARCH.md:654
SLACK_MCP_XOXB_TOKEN=xoxb-your-bot-token
MEDIUMSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
commands/init.md:35
curl -LsSf https://astral.sh/uv/install.sh | sh
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
worktree_remove, write_file
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmodules
.gitmodules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
desktop/.prettierignore
.prettierignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
desktop/.prettierrc.json
.prettierrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/plan_cascade/core/changed_files.py:194
staged_hash = hashlib.md5(staged_diff.encode()).hexdigest()[:8] if exit_code == 0 else "none"
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/plan_cascade/core/changed_files.py:198
unstaged_hash = hashlib.md5(unstaged_diff.encode()).hexdigest()[:8] if exit_code == 0 else "none"
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/plan_cascade/core/changed_files.py:202
return hashlib.md5(combined.encode()).hexdigest()

Gates applied: critical_finding, no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 30812261d5e4full audit observations/trust-audit/mcp-server/taoidle__plan-cascade.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0730812261d5e4BLOCKF43first audit
06

Questions

What is the Plan Cascade MCP server?

AI-powered cascading development framework. Decompose complex projects into parallel executable tasks with auto-generated PRDs, design docs, and multi-agent collaboration (Claude Code, Codex, Aider).

What tools does Plan Cascade expose?

55 in total: 38 read-only, 15 that write, and 2 that can delete or overwrite (worktree_remove, write_file). Every one is listed on this page with its risk.

Is Plan Cascade safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (43/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Plan Cascade need?

It reads ANTHROPIC_API_KEY, DASHSCOPE_API_KEY, DEEPSEEK_API_KEY, GLM_API_KEY, NOVITA_API_KEY and OPENAI_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Plan Cascade run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as plan-cascade-desktop at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (30812261d5e4), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement