Atlas / MCP servers / vitalyrodnenko / OmniFocus

OmniFocusSAFE

mcp/vitalyrodnenko/omnifocus-5

Model Context Protocol (MCP) server for OmniFocus on macOS, with Rust, Python, and TypeScript implementations

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
48 23r · 15w · 10d
Transport
stdio
License
MIT
Stars
43
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.omnigroup.com/omnifocus) [](https://modelcontextprotocol.io) [](#implementations) [](LICENSE)

MCP server that gives AI assistants full control over OmniFocus on macOS.

45 tools, 3 resources, and 4 prompts covering tasks, projects, tags, folders, perspectives, forecast, notifications, and review workflows — all through the Model Context Protocol.

This project is not affiliated with, endorsed by, or associated with The Omni Group or OmniFocus. OmniFocus is a trademark of The Omni Group. This is an independent, non-commercial open-source project.

Quick Start

Install via Homebrew (if you don't have Homebrew, see the Homebrew installation guide):

brew tap vitalyrodnenko/omnifocus-mcp
brew install omnifocus-mcp

Then add to your MCP client config (Claude Desktop, Cursor, etc.):

{
"mcpServers": {
"omnifocus": {
"command": "omnifocus-mcp",
"args": []
}
}
}

That's it. The AI assistant now has full OmniFocus access.

What It Can Do

Tasks (23 tools)

Full lifecycle management for OmniFocus tasks:

  • CRUD — create, get, update, delete individual tasks
  • Batch operations — create, move, or delete multiple tasks in a single call
  • Subtasks — create and list subtasks under any parent task
  • Completion — mark complete, mark incomplete (supports repeating tasks)
  • Search — full-text search across task names and notes with all filters applied
  • Move and reparent — relocate tasks between projects, reparent tasks under other tasks, or move subtask
Read from source at commit b59f18a2e80aOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add omnifocus-mcp-typescript -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "omnifocus-mcp-typescript": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (48)

23 read · 15 write · 10 destructive. Blast radius: 10 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_notificationwriteadd a notification to a task by id. provide exactly one of absoluteDate or relativeOffset.
append_to_notereadappend text to a task or project note by object id.
complete_projectreadcomplete a project by id or name. use this for finished/closed projects (done/completed), not set_project_status(\
complete_taskreadmark a task complete by id. use this for done/completed task lifecycle updates.
create_folderwritecreate a folder with optional parent folder and return id/name.
create_projectwritecreate a new project with optional folder, note, dates, and sequential mode.
create_subtaskwritecreate a new subtask under an existing parent task by id.
create_tagwritecreate a tag with optional parent tag and return id/name.
create_taskwritecreate a new task in inbox or a named project and return the created task summary.
create_tasks_batchwritecreate multiple tasks in one call and return created task summaries.
delete_folderdestructivedelete a folder by id or name. warning: this permanently removes the folder. do not use delete+recreate for folder edits or renames; use update_folder instead. contained projects may be moved to top level by omnifocus, so confirm with the user before proceeding.
delete_folders_batchdestructive
delete_projectdestructive
delete_projects_batchdestructive
delete_tagdestructivedelete a tag by id or name. warning: tasks using this tag will lose the tag assignment.
delete_tags_batchdestructivedelete multiple tags by id or exact name in a single omnijs call. destructive operation: this removes tags and unassigns them from linked tasks. use update_tag for non-destructive edits. before calling this tool, always show the user the target tag list and ask for explicit confirmation.
delete_taskdestructivedelete a task by id and return deletion status. destructive operation: use update_task or move_task for edits/reorganization, and never delete then recreate as a substitute for updating. ask for explicit user confirmation before proceeding.
delete_tasks_batchdestructive
duplicate_taskreadduplicate a task with all its properties. if the task has subtasks, they are cloned too by default.
get_folderreadget a folder by id or name with direct child projects and subfolders.
get_forecastreadget forecast sections for overdue, due today, flagged, deferred, and due-this-week tasks.
get_inboxreadget inbox tasks from omnifocus. returns unprocessed tasks that have not been assigned to a project.
get_projectreadget full details for one project by id or name.
get_project_countsreadget aggregate project counts by status without listing individual projects.
get_taskreadget full details for one task by id. returns list_tasks fields plus children, parentName, sequential state, repetitionRule, and effective date/status fields.
get_task_countsreadget aggregate task counts for any filter combination without listing individual tasks. added_* and changed_* filters must be ISO 8601 date strings; changed means the task
list_foldersreadlist folder hierarchy and project counts.
list_notificationsreadlist active notifications for a task by id.
list_perspectivesreadlist available perspectives including built-in and custom perspectives.
list_projectsreadlist projects with optional folder and status filters. status semantics: completed means finished work, dropped means intentionally abandoned/cancelled, on_hold means paused, active means current.
list_subtasksreadlist direct subtasks for a task id.
list_tagsreadlist tags with availability counts and optional status filter.
list_tasksread
move_projectwritemove a project by id or name to a folder or top level.
move_taskwrite
move_tasks_batchwrite
remove_notificationdestructiveremove one notification from a task by id.
search_projectsreadsearch projects by query using omnifocus project matching.
search_tagsreadsearch tags by query using omnifocus tag matching.
search_tasksread
set_project_statuswriteset a project
set_task_repetitiondestructiveset or clear a task repetition rule by task id.
uncomplete_projectreadreopen a completed project by id or name and return active status (undo complete_project).
uncomplete_taskreadmark a completed task incomplete by id.
update_folderwriteupdate a folder by id or name.
update_projectwriteupdate a project by id or name, modifying only provided fields.
update_tagwriteupdate a tag by id or name.
update_taskwriteupdate one task with partial fields and return the updated task payload.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_folder, delete_folders_batch, delete_project, delete_projects_batch, delete_tag, delete_tags_batch, delete_task, delete_tasks_batch, remove_notification, set_task_repetition
Why it matters. 10 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
python/tests/test_tools_read.py:27
importlib.import_module(module_name), "run_omnijs", fake_run_omnijs
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
python/tests/test_tools_write.py:58
monkeypatch.setattr(importlib.import_module(module_name), "run_omnijs", fake_run_omnijs)
LOWCode injection · code.dynamic_import · CWE-78, CWE-94, CWE-95
python/tests/test_tools_write.py:687
monkeypatch.setattr(importlib.import_module(module_name), "run_omnijs", fake_run_omnijs)
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
typescript/package.json
@modelcontextprotocol/sdk, zod, @types/node, typescript, vitest
Why it matters. 5 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha b59f18a2e80afull audit observations/trust-audit/mcp-server/vitalyrodnenko__omnifocus-5.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08b59f18a2e80aSAFEB89first audit
06

Questions

What is the OmniFocus MCP server?

Model Context Protocol (MCP) server for OmniFocus on macOS, with Rust, Python, and TypeScript implementations

What tools does OmniFocus expose?

48 in total: 23 read-only, 15 that write, and 10 that can delete or overwrite (delete_folder, delete_folders_batch, delete_project, delete_projects_batch, delete_tag). Every one is listed on this page with its risk.

Is OmniFocus safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 10 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OmniFocus need?

No credential environment variables were found in its source, so it appears to need none.

How does OmniFocus run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as omnifocus-mcp-typescript at 0.1.0.

How current is this page?

The grade is for one exact copy of the source (b59f18a2e80a), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement