56
/ 100
26 days ago
pulsemcp

Asana

Full-featured Asana integration with 80 tools covering tasks, projects, portfolios, goals, custom fields, and team management.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Known vulnerabilities in dependencies: 1 critical, 6 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 1 credential: ASANA_ACCESS_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical6 high

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

critical@modelcontextprotocol/inspector@0.4.0GHSA-7f8r-222p-6f5g

MCP Inspector proxy server lacks authentication between the Inspector client and proxy

high@xmldom/xmldom@0.8.11GHSA-2v35-w6hq-6mfw

xmldom: Uncontrolled recursion in XML serialization leads to DoS

high@xmldom/xmldom@0.8.11GHSA-f6ww-3ggp-fr8h

xmldom has XML injection through unvalidated DocumentType serialization

high@xmldom/xmldom@0.8.11GHSA-j759-j44w-7fr8

xmldom has XML node injection through unvalidated comment serialization

high@xmldom/xmldom@0.8.11GHSA-wh4c-j3r5-mjhp

xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretASANA_ACCESS_TOKEN"": "your-asana-access-token"
configASANA_DEFAULT_WORKSPACE_GIDNo Default workspace GID — tools use this when no workspace is specified
configASANA_READ_ONLY_MODENo Set to true to disable all write operations (great for safe exploration)
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 3 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/blzvi-asana-mcp-server-4ztpuu)](https://m8ven.ai/mcp/blzvi-asana-mcp-server-4ztpuu)
commit: d88977275f9fd81832301d7bd4c5cbe2179ddbd7
code hash: 82388cba314647efa3512ca7df9ea4e7f0e4bf83eb0544159389c2fc2b7c4ded
verified: 7/5/2026, 9:09:47 AM
view raw JSON →