OmniFocusSAFE
Let LLMs interface with your tasks and projects through the Model Context Protocol. Add, organize, and query your OmniFocus database with natural language commands.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://www.npmjs.com/package/omnifocus-mcp) [](https://github.com/themotionmachine/OmniFocus-MCP/actions/workflows/ci.yml)
A Model Context Protocol (MCP) server that connects OmniFocus to Claude and other MCP-compatible AI assistants.
Overview
This server bridges AI assistants and your OmniFocus database. Through natural conversation, an assistant can query, create, edit, and remove tasks and projects — including bulk operations. Some things you can do with it:
- Translate a syllabus PDF into a fully specified project with tasks, tags, defer dates, and due dates
- Turn a meeting transcript into a list of actions
- Audit and reorganize your tags, projects, and folders conversationally
- Create visualizations of your tasks, projects, and tags
- Process dozens of items in a single batch operation
Quick Start
Prerequisites
- macOS with OmniFocus installed
- Node.js 20 or later (for
npx)
The first time the server talks to OmniFocus, macOS will ask you to allow automation access. Grant it once and you're set.
Claude Desktop
Add the server to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"omnifocus": {
"command": "npx",
"args": ["-y", "omnifocus-mcp"]
}
}
}Then restart Claude Desktop.
Claude Code
claude mcp add omnifocus -- npx -y omnifocus-mcp
Other MCP clients work the same way: launch npx -y omnifocus-mcp over stdio.
Example Conversations
Targeted queries:
"Show me all my flagged tasks due this week" "What are my next actions in the Work folder?" "Count how many tasks are in each project"
Reorganizing:
"I want every task to have an energy level tag. Show m
c93b99522503OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add omnifocus-mcp -- npx -y [email protected]
{
"mcpServers": {
"omnifocus-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (12)
5 read · 5 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_omnifocus_task | write | Create a NEW task. If a matching task already exists (e.g. in the Inbox), do NOT create a duplicate — MOVE it with edit_item + newProjectName. When unsure, check with query_omnifocus first. |
add_project | write | Add a new project to OmniFocus |
batch_add_items | write | Add multiple tasks or projects to OmniFocus in a single operation |
batch_remove_items | destructive | Remove multiple tasks or projects from OmniFocus in a single operation |
create_tag | write | Create a new tag in OmniFocus, optionally nested under an existing parent tag |
dump_database | read | Gets the current state of your OmniFocus database |
edit_item | write | Edit an existing task or project. Also how you MOVE a task: set newProjectName (or \ |
get_perspective_view | read | Get the items visible in a named OmniFocus perspective |
list_perspectives | read | List built-in and custom perspectives (custom is a Pro feature) |
list_tags | read | List all tags with their hierarchy |
query_omnifocus | read | Query tasks, projects, or folders with filters (project, folder, tags, status, dates). Much faster and lighter than dump_database for targeted lookups. |
remove_item | destructive | Remove a task or project from OmniFocus |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
batch_remove_items, remove_item
const checkDateFilter = new Function(`${src}; return checkDateFilter;`)() as (d: Date, n: number) => boolean;const anchor = new Function('Task', `return ${js}`)(Task) as string;const result = new Function('Task', `return ${js}`)(Task);const format = new Function(`${src}; return formatReviewInterval;`)() as (ri: unknown) => string | null;return new Function('Task', 'inbox', 'moveTasks', `return ${js}`)(world.Task, world.inbox, world.moveTasks) as string;import { addOmniFocusTask } from '../../tools/primitives/addOmniFocusTask.js';import { addProject } from '../../tools/primitives/addProject.js';import { editItem } from '../../tools/primitives/editItem.js';import { removeItem } from '../../tools/primitives/removeItem.js';import { batchAddItems } from '../../tools/primitives/batchAddItems.js';@modelcontextprotocol/sdk, zod, @types/node, typescript, vitest
assets/omnifocus-mcp-logo.png
Gates applied: no_behavioural_pass.
c93b99522503full audit observations/trust-audit/mcp-server/themotionmachine__omnifocus.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | c93b99522503 | SAFE | B | 89 | first audit |
Questions
What is the OmniFocus MCP server?
Let LLMs interface with your tasks and projects through the Model Context Protocol. Add, organize, and query your OmniFocus database with natural language commands.
What tools does OmniFocus expose?
12 in total: 5 read-only, 5 that write, and 2 that can delete or overwrite (batch_remove_items, remove_item). Every one is listed on this page with its risk.
Is OmniFocus safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does OmniFocus need?
No credential environment variables were found in its source, so it appears to need none.
How does OmniFocus run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as omnifocus-mcp at 1.17.0.
How current is this page?
The grade is for one exact copy of the source (c93b99522503), read on 2026-10-06. The repository is watched and re-audited when it changes.