← Back to search

backlog-mcp

GitHub Actions Scanned 11d ago

Minimal task backlog MCP server for Claude and AI agents

C
61.7 / 100

Versions

0.70.0latest
Jul 20, 2026
0.69.0
Jul 19, 2026
0.68.0
Jul 18, 2026
0.67.0
Jul 18, 2026
0.66.0
Jul 17, 2026
+ show 86 moreshow less
0.65.0
Jul 17, 2026
0.64.0
Jul 17, 2026
0.63.0
Jul 17, 2026
0.62.0
Jul 17, 2026
0.61.0
Jul 16, 2026
0.60.0
Jul 16, 2026
0.59.0
Jul 16, 2026
0.58.0
Jun 19, 2026
0.57.0
Jun 19, 2026
0.56.0
Jun 19, 2026
0.55.1
Jun 19, 2026
0.55.0
Jun 19, 2026
0.54.1
Jun 19, 2026
0.53.7
Jun 18, 2026
0.53.6
Jun 18, 2026
0.53.5
Jun 18, 2026
0.53.3
Jun 18, 2026
0.53.2
Jun 18, 2026
0.53.1
Jun 18, 2026
0.53.0
Jun 17, 2026
0.52.0
Jun 17, 2026
0.51.1
Jun 17, 2026
0.51.0
Jun 16, 2026
0.50.3
Jun 3, 2026
0.50.2
May 25, 2026
0.50.1
May 25, 2026
0.50.0
May 25, 2026
0.49.2
Apr 29, 2026
0.49.0
Apr 29, 2026
0.48.2
Apr 23, 2026
0.48.1
Apr 20, 2026
0.47.5
Apr 14, 2026
0.47.4
Apr 14, 2026
0.47.3
Apr 14, 2026
0.47.2
Apr 14, 2026
0.47.1
Mar 26, 2026
0.47.0
Mar 26, 2026
0.46.0
Feb 24, 2026
0.45.0
Feb 24, 2026
0.43.0
Feb 24, 2026
0.42.0
Feb 24, 2026
0.41.0
Feb 24, 2026
0.40.0
Feb 21, 2026
0.39.1
Feb 20, 2026
0.39.0
Feb 16, 2026
0.37.0
Feb 16, 2026
0.36.0
Feb 12, 2026
0.35.0
Feb 10, 2026
0.34.0
Feb 9, 2026
0.33.0
Feb 7, 2026
0.32.0
Feb 6, 2026
0.31.0
Feb 5, 2026
0.30.0
Feb 5, 2026
0.29.1
Feb 3, 2026
0.29.0
Feb 3, 2026
0.28.0
Jan 31, 2026
0.27.2
Jan 29, 2026
0.27.1
Jan 28, 2026
0.27.0
Jan 28, 2026
0.26.1
Jan 27, 2026
0.26.0
Jan 27, 2026
0.25.1
Jan 27, 2026
0.25.0
Jan 26, 2026
0.24.0
Jan 26, 2026
0.23.0
Jan 26, 2026
0.21.0
Jan 26, 2026
0.20.0
Jan 25, 2026
0.19.0
Jan 24, 2026
0.18.0
Jan 24, 2026
0.17.0
Jan 23, 2026
0.16.0
Jan 22, 2026
0.14.0
Jan 22, 2026
0.13.0
Jan 22, 2026
0.12.0
Jan 21, 2026
0.11.3
Jan 21, 2026
0.10.0
Jan 20, 2026
0.9.0
Jan 20, 2026
0.8.1
Jan 17, 2026
0.8.0
Jan 17, 2026
0.7.0
Jan 17, 2026
0.6.7
Jan 17, 2026
0.6.5
Jan 16, 2026
0.2.1
Jan 11, 2026
0.2.0
Dec 27, 2025
0.1.2
Dec 27, 2025
0.1.0
Dec 27, 2025
PermissionsTool SafetyAuthAnnotationsCode QualityStabilitySpecVuln HistoryAuthorTransparencyCommunity

Tools 11

backlog_wakeup
annotations: none low

Dense session-start briefing: active tasks, current epics, project constraints (requirements as stubs, violated/at-risk first — treat these as standing product intent), recent completions (with evidence snippets), recent activity, and the home-wide unfiled work count. No focal entity required — use this at the start of every session to understand what you were working on. Optional `scope` narrows the entity sections to a folder, milestone, or epic; unfiled remains home-wide because parentless work has no subtree ancestry. Optional `operation` resumes a mid-flight operation document: its live state becomes the briefing\'s FOCUS centerpiece and the rest of the briefing yields budget to it.

write_resource
annotations: none low

Use when you want backlog-mcp to validate and canonically persist an existing entity edit before reporting success. For ordinary repository prose edits, use your native Edit tool; reconciliation updates indexes and diagnostics afterward. Create and transition entities through the substrate-declared intent tools. * The \

backlog_list
annotations: none low

List backlog entities from the active project substrate registry. Returns most recently observed items first, limited to 20 by default.

backlog_search
annotations: none low

Search across all indexed backlog substrates and generic resources. Returns relevance-ranked results with match context. Use this for discovery; use backlog_list for filtering by status/type.

backlog_recall
annotations: none low

Recall memories — knowledge and episodes captured across sessions. Returns STUBS (title + one-line digest + provenance) by default; expand interesting ones with backlog_get(MEMO-id), or pass full:true for bodies. Weigh a stub\'s trust BEFORE hydrating: age_days (on the knowledge\'s own timeline), uses/idle_days (recall demand), supersedes (this is a correction), derived (consolidator inference), kind (current/historical/plan/preference/timeless). Old + never-used = treat as hypothesis, not truth. Distinct from backlog_search (live entities). Use to answer "how do we deploy?", "have I hit this before?", "what did I finish about X?". Memories point back to source entities via entity_id.

backlog_consolidation_candidates
annotations: none low

List clusters of episodic memories that are ripe for consolidation into durable knowledge.

backlog_get
annotations: none low

Get full details by ID. Accepts task IDs (TASK-0001, EPIC-0002), document paths (README.md, docs/adr/0001-example.md), or MCP resource URIs (mcp://backlog/resources/design.md). Works for any item regardless of status. Pass context:true when starting work on an entity to also see its relational neighborhood as stubs.

backlog_forget
annotations: none low

Retract memories — soft-expire them so recall stops returning them (the record stays auditable in the viewer). Use when knowledge is wrong or obsolete and there is no replacement (if there IS a replacement, use backlog_remember with supersedes instead). expired:true garbage-collects already-expired memories.

backlog_delete
annotations: none low

Delete an item permanently.

backlog_remember
annotations: none low

Write a durable memory — a stable fact, a procedure, or a preference you should know next session. Use when you learn something worth keeping: "this repo deploys via wrangler", "Goga prefers terse evidence bullets". To CORRECT existing knowledge, pass supersedes (the old MEMO- id is expired, lineage kept) or state_key (previous holders of the same evolving fact are closed). The optional collision_candidates receipt is tri-state: [] means the advisory scan completed clean; a non-empty array means nearby facts deserve adjudication; absent means the advisory scan did not run or failed, not that the write failed. Do not use for task events — completions are captured automatically.

backlog_contradictions
annotations: none low

List structural contradictions in memory: sets of ≥2 LIVE memories that share one state_key (e.g. "db.primary"),

Permissions 4

network medium
Server uses network capabilities via: fetch()
filesystem low
Server uses filesystem capabilities via: fs
shell high
Server uses shell capabilities via: child_process, execSync(), spawn(), spawnSync()
env_vars low
Server uses env_vars capabilities via: process.env

Scan Findings 133

medium
Vulnerable dependency: vite@7.1.5 (GHSA-4w7w-66w2-5vf9) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@7.1.5 (GHSA-93m4-6634-74q7) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@7.1.5 (GHSA-fx2h-pf6j-xcff) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@7.1.5 (GHSA-p9ff-h696-f583) dependency_analyzer · 95%
low
Tool 'backlog_wakeup' has no annotations annotation_checker · 100%
low
Tool 'write_resource' has no annotations annotation_checker · 100%
low
Tool 'backlog_list' has no annotations annotation_checker · 100%
low
Tool 'backlog_search' has no annotations annotation_checker · 100%
low
Tool 'backlog_recall' has no annotations annotation_checker · 100%
low
Tool 'backlog_consolidation_candidates' has no annotations annotation_checker · 100%
low
Tool 'backlog_get' has no annotations annotation_checker · 100%
low
Tool 'backlog_forget' has no annotations annotation_checker · 100%
low
Tool 'backlog_delete' has no annotations annotation_checker · 100%
low
Tool 'backlog_remember' has no annotations annotation_checker · 100%
low
Tool 'backlog_contradictions' has no annotations annotation_checker · 100%
high
Hardcoded OAuth client secret in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/oauth-refresh.test.ts auth_checker · 95%
info
Sandbox failed to start for behavioral verification behavioral_verifier · 100%
medium
Vulnerable dependency: vite@7.1.5 (GHSA-v2wj-q39q-566r) dependency_analyzer · 95%
medium
Vulnerable dependency: vite@7.1.5 (GHSA-v6wh-96g9-6wx3) dependency_analyzer · 95%
medium
Vulnerable dependency: vitest@2.1.9 (GHSA-5xrq-8626-4rwp) dependency_analyzer · 95%
medium
Vulnerable dependency: @hono/node-server@1.14.0 (GHSA-92pp-h63x-v22m) dependency_analyzer · 95%
medium
Vulnerable dependency: @hono/node-server@1.14.0 (GHSA-frvp-7c67-39w9) dependency_analyzer · 95%
medium
Vulnerable dependency: @hono/node-server@1.14.0 (GHSA-wc8c-qw6v-h7f6) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.25.1 (GHSA-345p-7cg4-v4c7) dependency_analyzer · 95%
medium
Vulnerable dependency: @modelcontextprotocol/sdk@1.25.1 (GHSA-8r9q-7v3j-jr4g) dependency_analyzer · 95%
medium
Vulnerable dependency: ajv@8.17.1 (GHSA-2g4f-4pwh-qvx6) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-26pp-8wgv-hjvm) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-2gcr-mfcq-wcc3) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-3hrh-pfw6-9m5x) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-3vhc-576x-3qv4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-458j-xx4x-4375) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-5pq2-9x2x-5p6w) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-69xw-7hcm-h432) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-6wqw-2p9w-4vw4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-79qm-7rj5-m7r9) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-88fw-hqm2-52qc) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-8j4g-w8fx-2239) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-92vj-g62v-jqhh) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-9r54-q6cx-xmh5) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-9vqf-7f2p-gf9v) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-f23p-vx2j-j53r) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-f577-qrjj-4474) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-f67f-6cw9-8mq4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-gq3j-xvxp-8hrf) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-hm8q-7f3q-5f36) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-j6c9-x7qj-28xf) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-m732-5p4w-x69g) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-p6xx-57qc-3wxr) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-p77w-8qqv-26rm) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-q5qw-h33p-qvwr) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-q7jf-gf43-6x6p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-qp7p-654g-cw7p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-r354-f388-2fhh) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-r5rp-j6wh-rvv4) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-rv63-4mwf-qqc2) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-v8w9-8mx6-g223) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-w332-q679-j88p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-w62v-xxxg-mg59) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-wgpf-jwqj-8h8p) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-wmmm-f939-6g9c) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-wwfh-h76j-fc44) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-xf4j-xp2r-rqqx) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-xgm2-5f3f-mvvc) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-xpcf-pg52-r92g) dependency_analyzer · 95%
medium
Vulnerable dependency: hono@4.7.0 (GHSA-xrhx-7g5j-rcj5) dependency_analyzer · 95%
medium
Vulnerable dependency: wrangler@4.0.0 (GHSA-36p8-mvp6-cv38) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-39q2-94rc-95cp) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-55q2-fjhq-7xh7) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-76mc-f452-cxcm) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-c2j3-45gr-mqc4) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-cj63-jhhr-wcxv) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-cjmm-f4jc-qw8r) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-cmwh-pvxp-8882) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-crv5-9vww-q3g8) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-gvmj-g25r-r7wr) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-h7mw-gpvr-xq4m) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-h8r8-wccr-v5f2) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-hpcv-96wg-7vj8) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-r47g-fvhr-h676) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-rp9w-3fw7-7cwq) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-v2wj-7wpq-c8vv) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-v9jr-rg53-9pgp) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-vxr8-fq34-vvx9) dependency_analyzer · 95%
medium
Vulnerable dependency: dompurify@3.3.1 (GHSA-x4vx-rjvf-j5p4) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-2v8p-3f2j-5mp7) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-3rrr-jr9j-h3q3) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-6m6c-36f7-fhxh) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-6x64-9x62-f2gx) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-87f9-hvmw-gh4p) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-c4c3-pg64-4m4v) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-ghcm-xqfw-q4vr) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-rhh3-jpg6-66xh) dependency_analyzer · 95%
medium
Vulnerable dependency: mermaid@11.12.3 (GHSA-xcj9-5m2h-648r) dependency_analyzer · 95%
medium
Vulnerable dependency: happy-dom@20.5.3 (GHSA-6q6h-j7hj-3r64) dependency_analyzer · 95%
medium
Vulnerable dependency: happy-dom@20.5.3 (GHSA-w4gp-fjgq-3q4g) dependency_analyzer · 95%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:290 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:296 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:302 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:308 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:314 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:320 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:326 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:332 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:338 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:344 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:350 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:356 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:362 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:368 entropy_analyzer · 70%
info
Tool: backlog_delete manifest_parser · 85%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:374 entropy_analyzer · 70%
medium
Hex string literal (>50 chars) in gkoreli-backlog-mcp-135db9d/packages/server/src/__tests__/register-substrate-intents.test.ts:380 entropy_analyzer · 70%
info
package.json metadata manifest_parser · 100%
info
Tool: backlog_wakeup manifest_parser · 85%
info
Tool: write_resource manifest_parser · 85%
info
Tool: backlog_list manifest_parser · 85%
info
Tool: backlog_search manifest_parser · 85%
info
Tool: backlog_recall manifest_parser · 85%
info
Tool: backlog_consolidation_candidates manifest_parser · 85%
info
Tool: backlog_get manifest_parser · 85%
info
Tool: backlog_forget manifest_parser · 85%
info
Tool: backlog_remember manifest_parser · 85%
info
Tool: backlog_contradictions manifest_parser · 85%
info
Transport: streamable-http manifest_parser · 80%
info
Required env vars (21) manifest_parser · 80%
info
Sandbox failed to start for output poisoning scan output_poisoning · 100%
medium
Permission: network access detected permission_analyzer · 70%
low
Permission: filesystem access detected permission_analyzer · 90%
high
Permission: shell access detected permission_analyzer · 95%
low
Permission: env_vars access detected permission_analyzer · 90%
info
SBOM generated: 36 components sbom_generator · 100%
high
Hardcoded Password found in gkoreli-backlog-mcp-135db9d/docs/adr/0021-chatgpt-apps-sdk-integration.md secret_scanner · 65%
medium
No build provenance detected (SLSA L0) slsa_assessor · 90%