Atlas / MCP servers / teamwork / Teamwork

TeamworkCAUTION

mcp/teamwork/teamwork-1

Teamwork.com MCP server

Verdict
CAUTION
Grade
C
Trust score
79 /100
Exposed tools
—
Transport
sse · stdio · streamable-http
License
MIT
Stars
26
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Model Context Protocol server for Teamwork.com integration with Large Language Models

[](https://goreportcard.com/report/github.com/teamwork/mcp) [](https://golang.org/) [](https://modelcontextprotocol.io/)

📌 Are you a Teamwork.com user wanting to connect AI tools to your Teamwork.com site right now? Jump straight to the Usage Guide for tokens, enabling MCP, and client configuration examples.

📖 Overview

This MCP (Model Context Protocol) server enables seamless integration between Large Language Models and Teamwork.com. It provides a standardized interface for LLMs to interact with Teamwork.com projects, allowing AI agents to perform various project management operations.

🤖 What is MCP?

Model Context Protocol (MCP) is an open protocol that standardizes how applications provide context to LLMs. This server describes all the actions available in Teamwork.com (tools) in a way that LLMs can understand and execute through AI agents.

✨ Features

  • Multiple Transport Modes: HTTP and STDIO interfaces for different deployment scenarios
  • Secure Authentication: Bearer token and OAuth2 integration with Teamwork.com
  • Tool Framework: Extensible toolset architecture for adding new capabilities
  • Production Ready: Comprehensive logging, monitoring, and observability
  • Read-Only Mode: Optional restriction to read-only operations for safety

See the auto-generated Tool Reference for every create/read/update operation exposed across Projects, Desk, Spaces, and Chat, or browse the same catalogue with per-tool descriptions and a search filter at [teamwork.github.io/mcp](https://teamwork.github.io/mcp/).

🚀 Available Servers

This project provides three different ways to inte

Read from source at commit 17ab104fa9e9OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add mcp:v1.0.0 --env TW_MCP_BEARER_TOKEN=${TW_MCP_BEARER_TOKEN} -- docker run -i --rm docker.io/teamwork/mcp:v1.0.0:None
03

Trust audit

CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (16)

HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
docs/usage/chat-gpt.md:10
- Developer mode enabled in your workspace settings
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWInventory / provenance · inv.hidden_file · CWE-1104
.golangci.yml
.golangci.yml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cmd/docs-gen/html_test.go:15
const htmlPath = "../../docs/index.html"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cmd/docs-gen/main_test.go:18
const docPath = "../../docs/tool-reference.md"
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
cmd/next-version/main_test.go:100
doc, err := os.ReadFile("../../CONTRIBUTING.md")
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
internal/twprojects/files_test.go:91
input: "../../etc/passwd",
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
internal/twprojects/timelogs_summary_test.go:126
t.Errorf("logged minutes: Σgroups=%d totals=%d", logged, res.Totals.LoggedMinutes)
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
internal/twprojects/timelogs_summary_test.go:129
t.Errorf("billable minutes: Σgroups=%d totals=%d", billable, res.Totals.BillableMinutes)
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
internal/twprojects/timelogs_summary_test.go:132
t.Errorf("non-billable minutes: Σgroups=%d totals=%d", nonBillable, res.Totals.NonBillableMinutes)
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
internal/twprojects/timelogs_summary_test.go:135
t.Errorf("billed minutes: Σgroups=%d totals=%d", billed, res.Totals.BilledMinutes)
LOWObfuscation / stealth · obf.homoglyph · CWE-506, CWE-94
internal/twprojects/timelogs_summary_test.go:138
t.Errorf("unbilled-billable minutes: Σgroups=%d totals=%d", unbilled, res.Totals.UnbilledBillableMinutes)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/nodejs-langchain/package.json
@langchain/anthropic, @langchain/core, @langchain/google-genai, @langchain/langgraph, @langchain/mcp-adapters, @langchain/openai, @types/node, commander
Why it matters. 11 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
examples/python-langchain/requirements.txt
langchain, langchain-mcp-adapters, langchain-anthropic, langchain-openai, langchain-google-genai
Why it matters. 5 requirement(s) not pinned with ==
Fix. pin exact versions
LOWInventory / provenance · mcp.no_tools_extracted · CWE-1104
server.json
Why it matters. the tool list is enumerated at runtime by tools/list, not declared in source
Fix. the page says so rather than showing an empty table
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
cmd/mcp-stdio/README.md:84
| `ops`             | All sub-toolsets                                                                     | Full access — same as `all`                   |

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 17ab104fa9e9full audit observations/trust-audit/mcp-server/teamwork__teamwork-1.json · Report an issue / request a re-scan
04

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0917ab104fa9e9CAUTIONC79first audit
05

Questions

What is the Teamwork MCP server?

Teamwork.com MCP server

Is Teamwork safe to connect to an agent?

With care. The audit graded it C (79/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Teamwork need?

It reads TW_MCP_BEARER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Teamwork run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as nodejs-langchain at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (17ab104fa9e9), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement