Atlas / MCP servers / themotionmachine / OmniFocus

OmniFocusSAFE

mcp/themotionmachine/omnifocus

Let LLMs interface with your tasks and projects through the Model Context Protocol. Add, organize, and query your OmniFocus database with natural language commands.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 5r · 5w · 2d
Transport
stdio
License
MIT
Stars
244
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/omnifocus-mcp) [](https://github.com/themotionmachine/OmniFocus-MCP/actions/workflows/ci.yml)

A Model Context Protocol (MCP) server that connects OmniFocus to Claude and other MCP-compatible AI assistants.

Overview

This server bridges AI assistants and your OmniFocus database. Through natural conversation, an assistant can query, create, edit, and remove tasks and projects — including bulk operations. Some things you can do with it:

  • Translate a syllabus PDF into a fully specified project with tasks, tags, defer dates, and due dates
  • Turn a meeting transcript into a list of actions
  • Audit and reorganize your tags, projects, and folders conversationally
  • Create visualizations of your tasks, projects, and tags
  • Process dozens of items in a single batch operation

Quick Start

Prerequisites

  • macOS with OmniFocus installed
  • Node.js 20 or later (for npx)

The first time the server talks to OmniFocus, macOS will ask you to allow automation access. Grant it once and you're set.

Claude Desktop

Add the server to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
"mcpServers": {
"omnifocus": {
"command": "npx",
"args": ["-y", "omnifocus-mcp"]
}
}
}

Then restart Claude Desktop.

Claude Code

claude mcp add omnifocus -- npx -y omnifocus-mcp

Other MCP clients work the same way: launch npx -y omnifocus-mcp over stdio.

Example Conversations

Targeted queries:

"Show me all my flagged tasks due this week" "What are my next actions in the Work folder?" "Count how many tasks are in each project"

Reorganizing:

"I want every task to have an energy level tag. Show m
Read from source at commit c93b99522503OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add omnifocus-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "omnifocus-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (12)

5 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_omnifocus_taskwriteCreate a NEW task. If a matching task already exists (e.g. in the Inbox), do NOT create a duplicate — MOVE it with edit_item + newProjectName. When unsure, check with query_omnifocus first.
add_projectwriteAdd a new project to OmniFocus
batch_add_itemswriteAdd multiple tasks or projects to OmniFocus in a single operation
batch_remove_itemsdestructiveRemove multiple tasks or projects from OmniFocus in a single operation
create_tagwriteCreate a new tag in OmniFocus, optionally nested under an existing parent tag
dump_databasereadGets the current state of your OmniFocus database
edit_itemwriteEdit an existing task or project. Also how you MOVE a task: set newProjectName (or \
get_perspective_viewreadGet the items visible in a named OmniFocus perspective
list_perspectivesreadList built-in and custom perspectives (custom is a Pro feature)
list_tagsreadList all tags with their hierarchy
query_omnifocusreadQuery tasks, projects, or folders with filters (project, folder, tags, status, dates). Much faster and lighter than dump_database for targeted lookups.
remove_itemdestructiveRemove a task or project from OmniFocus
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (13)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
batch_remove_items, remove_item
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/tools/__tests__/queryOmnifocus.test.ts:768
const checkDateFilter = new Function(`${src}; return checkDateFilter;`)() as (d: Date, n: number) => boolean;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/utils/__tests__/repetitionRule.test.ts:133
const anchor = new Function('Task', `return ${js}`)(Task) as string;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/utils/__tests__/reviewInterval.test.ts:36
const result = new Function('Task', `return ${js}`)(Task);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/utils/__tests__/reviewInterval.test.ts:89
const format = new Function(`${src}; return formatReviewInterval;`)() as (ri: unknown) => string | null;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
src/utils/__tests__/taskMove.test.ts:117
return new Function('Task', 'inbox', 'moveTasks', `return ${js}`)(world.Task, world.inbox, world.moveTasks) as string;
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/integration/setup.ts:4
import { addOmniFocusTask } from '../../tools/primitives/addOmniFocusTask.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/integration/setup.ts:5
import { addProject } from '../../tools/primitives/addProject.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/integration/setup.ts:6
import { editItem } from '../../tools/primitives/editItem.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/integration/setup.ts:7
import { removeItem } from '../../tools/primitives/removeItem.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tests/integration/setup.ts:8
import { batchAddItems } from '../../tools/primitives/batchAddItems.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript, vitest
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
assets/omnifocus-mcp-logo.png
assets/omnifocus-mcp-logo.png
Why it matters. 1973221 bytes not read

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha c93b99522503full audit observations/trust-audit/mcp-server/themotionmachine__omnifocus.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-06c93b99522503SAFEB89first audit
06

Questions

What is the OmniFocus MCP server?

Let LLMs interface with your tasks and projects through the Model Context Protocol. Add, organize, and query your OmniFocus database with natural language commands.

What tools does OmniFocus expose?

12 in total: 5 read-only, 5 that write, and 2 that can delete or overwrite (batch_remove_items, remove_item). Every one is listed on this page with its risk.

Is OmniFocus safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OmniFocus need?

No credential environment variables were found in its source, so it appears to need none.

How does OmniFocus run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as omnifocus-mcp at 1.17.0.

How current is this page?

The grade is for one exact copy of the source (c93b99522503), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement