Index live · v1.7.0 · OCT 6 2026

Task Master

Verified
byeyaltoledano

PRD parsing and AI-driven development task management for Claude Code.

stdioTypeScript
25.5Kstars

Configuration

claude mcp add taskmaster-ai -- npx -y task-master-ai

Run in a terminal. Copied verbatim from the upstream README.

AgenticSkills Audit

Automated framework checks. Deep code review tracked separately. Read the methodology →

4/7
4 of 7 automated checks passed
Audited Aug 7, 2026
SECURITY.md published
Mitigates: Coordinated disclosure pathNo SECURITY.md in repo root, .github/, or docs/
Commit in last 90 days
Mitigates: Maintainer abandonmentLast push 100 day(s) ago (>90)
≥2 active contributors
Mitigates: Bus-factor of one10 contributors with ≥2 commits
Evidence
CI pipeline configured
Mitigates: Code health regression
Evidence
Dependency lockfile committed
Mitigates: Dependency confusionpackage-lock.json
Evidence
Software Bill of Materials (SBOM)
Mitigates: Audit trailNo SBOM file present
License declared
Mitigates: Legal ambiguityOther

Deep framework checks (OAuth 2.1 / PKCE implementation, input validation, sandboxing) require human source review and are tracked separately. This scorecard covers programmatically verifiable signals only.

Quick Stats

Trust LevelVerified
Stars25,500
Transportstdio
API KeyNot required
LanguageTypeScript
CategoryDeveloper Tools

Author

e

eyaltoledano

Tags

task-managementprddevelopmentplanning

Get new MCP servers in your inbox. What we added, what failed the security audit, and why. See a past issue.