TaskQueue (chriscarrollsmith/taskqueue-mcp) is an MCP server listed on the M8ven Trust Index. It scores 69 out of 100, grade C. It declares 14 tools. No publisher has claimed this listing.
Structured task management system that breaks down complex projects into manageable tasks with progress tracking, user approval checkpoints, and support for multiple LLM providers.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
chriscarrollsmith
Source: PulseMCP · also listed on mcp.so
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
list_projectsList all projects in the system and their basic information (ID, initial prompt, task counts), optionally filtered by state (open, pending_approval, completed, all).
read_projectRead all information for a given project, by its ID, including its tasks' statuses.
create_projectCreate a new project with an initial prompt and a list of tasks. This is typically the first step in any workflow.
delete_projectDelete a project and all its associated tasks.
add_tasks_to_projectAdd new tasks to an existing project.
finalize_projectMark a project as complete. Can only be called when all tasks are both done and approved. This is typically the last step in a project workflow.
generate_project_planUse an LLM to generate a project plan and tasks from a prompt. The LLM will analyze the prompt and any attached files to create a structured project plan.
list_tasksList all tasks, optionally filtered by project ID and/or state (open, pending_approval, completed, all). Tasks may include tool and rule recommendations to guide their completion.
read_taskGet details of a specific task by its ID. The task may include toolRecommendations and ruleRecommendations fields that should be used to guide task completion.
create_taskCreate a new task within an existing project. You can optionally include tool and rule recommendations to guide task completion.
update_taskModify a task's properties. Note: (1) completedDetails are required when setting status to 'done', (2) approved tasks cannot be modified, (3) status must follow valid transitions: not started → in progress → done. You can also update tool and rule recommendations to guide task completion.
delete_taskRemove a task from a project.
approve_taskApprove a completed task. Tasks must be marked as 'done' with completedDetails before approval. Note: This is a CLI-only operation that requires human intervention.
get_next_taskGet the next task to be done in a project. Returns the first non-approved task in sequence, regardless of status. The task may include toolRecommendations and ruleRecommendations fields that should be used to guide task completion.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Vercel’s AI SDK's filetype whitelists can be bypassed when uploading files
@babel/core: Arbitrary File Read via sourceMappingURL Comment
TASK_MANAGER_FILE_PATH"": "/path/to/tasks.json"XDG_DATA_HOMEProduction dependencies are patched
0 critical, 2 high severity in production deps — @modelcontextprotocol/sdk@1.8.0 (high), @modelcontextprotocol/sdk@1.8.0 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Dependency freshness
1/11 production deps stale: cli-table3@2024-05-12 (2.3y)
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/chriscarrollsmith/taskqueue-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check