TeamworkCAUTION
Teamwork.com MCP server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Model Context Protocol server for Teamwork.com integration with Large Language Models
[](https://goreportcard.com/report/github.com/teamwork/mcp) [](https://golang.org/) [](https://modelcontextprotocol.io/)
📌 Are you a Teamwork.com user wanting to connect AI tools to your Teamwork.com site right now? Jump straight to the Usage Guide for tokens, enabling MCP, and client configuration examples.
📖 Overview
This MCP (Model Context Protocol) server enables seamless integration between Large Language Models and Teamwork.com. It provides a standardized interface for LLMs to interact with Teamwork.com projects, allowing AI agents to perform various project management operations.
🤖 What is MCP?
Model Context Protocol (MCP) is an open protocol that standardizes how applications provide context to LLMs. This server describes all the actions available in Teamwork.com (tools) in a way that LLMs can understand and execute through AI agents.
✨ Features
- Multiple Transport Modes: HTTP and STDIO interfaces for different deployment scenarios
- Secure Authentication: Bearer token and OAuth2 integration with Teamwork.com
- Tool Framework: Extensible toolset architecture for adding new capabilities
- Production Ready: Comprehensive logging, monitoring, and observability
- Read-Only Mode: Optional restriction to read-only operations for safety
See the auto-generated Tool Reference for every create/read/update operation exposed across Projects, Desk, Spaces, and Chat, or browse the same catalogue with per-tool descriptions and a search filter at [teamwork.github.io/mcp](https://teamwork.github.io/mcp/).
🚀 Available Servers
This project provides three different ways to inte
17ab104fa9e9OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp:v1.0.0 --env TW_MCP_BEARER_TOKEN=${TW_MCP_BEARER_TOKEN} -- docker run -i --rm docker.io/teamwork/mcp:v1.0.0:NoneTrust audit
CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (16)
- Developer mode enabled in your workspace settings
.golangci.yml
CLAUDE.md
const htmlPath = "../../docs/index.html"
const docPath = "../../docs/tool-reference.md"
doc, err := os.ReadFile("../../CONTRIBUTING.md")input: "../../etc/passwd",
t.Errorf("logged minutes: Σgroups=%d totals=%d", logged, res.Totals.LoggedMinutes)t.Errorf("billable minutes: Σgroups=%d totals=%d", billable, res.Totals.BillableMinutes)t.Errorf("non-billable minutes: Σgroups=%d totals=%d", nonBillable, res.Totals.NonBillableMinutes)t.Errorf("billed minutes: Σgroups=%d totals=%d", billed, res.Totals.BilledMinutes)t.Errorf("unbilled-billable minutes: Σgroups=%d totals=%d", unbilled, res.Totals.UnbilledBillableMinutes)@langchain/anthropic, @langchain/core, @langchain/google-genai, @langchain/langgraph, @langchain/mcp-adapters, @langchain/openai, @types/node, commander
langchain, langchain-mcp-adapters, langchain-anthropic, langchain-openai, langchain-google-genai
| `ops` | All sub-toolsets | Full access — same as `all` |
Gates applied: instruction_override, no_behavioural_pass.
17ab104fa9e9full audit observations/trust-audit/mcp-server/teamwork__teamwork-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 17ab104fa9e9 | CAUTION | C | 79 | first audit |
Questions
What is the Teamwork MCP server?
Teamwork.com MCP server
Is Teamwork safe to connect to an agent?
With care. The audit graded it C (79/100) and found 16 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Teamwork need?
It reads TW_MCP_BEARER_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Teamwork run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as nodejs-langchain at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (17ab104fa9e9), read on 2026-10-09. The repository is watched and re-audited when it changes.