spatialy/huly-mcp (spatialy/huly-mcp) is an MCP server listed on the M8ven Trust Index. It scores 60 out of 100, grade C. It declares 164 tools. No publisher has claimed this listing.
MCP server for Huly platform enabling project management, issue tracking, and collaboration through natural language.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
spatialy
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
list_activityList activity messages for a Huly object. Returns activity sorted by date (newest first).
add_reactionAdd an emoji reaction to an activity message.
remove_reactionRemove an emoji reaction from an activity message.
list_reactionsList reactions on an activity message.
save_messageSave/bookmark an activity message for later reference.
unsave_messageRemove an activity message from saved/bookmarks.
list_saved_messagesList saved/bookmarked activity messages.
list_mentionsList @mentions of the current user in activity messages.
list_attachmentsList attachments on a Huly object (issue, document, etc.). Returns attachments sorted by modification date (newest first).
get_attachmentRetrieve full details for a Huly attachment including download URL.
add_attachmentAdd an attachment to a Huly object. Provide ONE of: filePath (local file - preferred), fileUrl (fetch from URL), or data (base64). Returns the attachment ID and download URL.
update_attachmentUpdate attachment metadata (description, pinned status).
delete_attachmentPermanently delete an attachment. This action cannot be undone.
pin_attachmentPin or unpin an attachment.
download_attachmentGet download URL for an attachment along with file metadata (name, type, size).
add_issue_attachmentAdd an attachment to a Huly issue. Convenience method that finds the issue by project and identifier. Provide ONE of: filePath, fileUrl, or data.
add_document_attachmentAdd an attachment to a Huly document. Convenience method that finds the document by teamspace and title/ID. Provide ONE of: filePath, fileUrl, or data.
list_eventsList calendar events. Returns events sorted by date. Supports filtering by date range.
get_eventRetrieve full details for a calendar event including description. Use this to view event content and metadata.
create_eventCreate a new calendar event. Description supports markdown formatting. Returns the created event ID.
update_eventUpdate fields on an existing calendar event. Only provided fields are modified. Description updates support markdown.
delete_eventPermanently delete a calendar event. This action cannot be undone.
list_recurring_eventsList recurring event definitions. Returns recurring events sorted by modification date (newest first).
create_recurring_eventCreate a new recurring calendar event with RFC5545 RRULE rules. Description supports markdown. Returns the created event ID.
list_event_instancesList instances of a recurring event. Returns instances sorted by date. Supports filtering by date range. Use includeParticipants=true to fetch full participant info (extra lookups).
list_card_typesList available card types (MasterTags) in the Huly workspace. Use this to discover what card types exist before creating or filtering cards.
list_cardsList cards in the Huly workspace. Optionally filter by card type ID. Returns cards sorted by modification date (newest first).
get_cardGet full details of a Huly card including markdown content. Look up by title or ID.
create_cardCreate a new card in the Huly workspace. Optionally specify a card type (MasterTag ID from list_card_types). Content supports markdown.
update_cardUpdate fields on an existing Huly card. Only provided fields are modified. Content updates support markdown.
delete_cardPermanently delete a Huly card. This action cannot be undone.
list_channelsList all Huly channels. Returns channels sorted by name. Supports filtering by archived status. Supports searching by name substring (nameSearch) and topic substring (topicSearch).
get_channelRetrieve full details for a Huly channel including topic and member list.
create_channelCreate a new channel in Huly. Returns the created channel ID and name.
update_channelUpdate fields on an existing Huly channel. Only provided fields are modified.
delete_channelPermanently delete a Huly channel. This action cannot be undone.
list_channel_messagesList messages in a Huly channel. Returns messages sorted by date (newest first).
send_channel_messageSend a message to a Huly channel. Message body supports markdown formatting.
list_direct_messagesList direct message conversations in Huly. Returns conversations sorted by date (newest first).
list_thread_repliesList replies in a message thread. Returns replies sorted by date (oldest first).
add_thread_replyAdd a reply to a message thread. Reply body supports markdown formatting.
update_thread_replyUpdate a thread reply. Only the body can be modified.
delete_thread_replyPermanently delete a thread reply. This action cannot be undone.
list_commentsList comments on a Huly issue. Returns comments sorted by creation date (oldest first).
add_commentAdd a comment to a Huly issue. Comment body supports markdown formatting.
update_commentUpdate an existing comment on a Huly issue. Comment body supports markdown formatting.
delete_commentDelete a comment from a Huly issue. This action cannot be undone.
list_personsList all persons in the Huly workspace. Returns persons sorted by modification date (newest first). Supports searching by name substring (nameSearch) and email substring (emailSearch).
get_personRetrieve full details for a person including contact channels. Use personId or email to identify the person.
create_personCreate a new person in Huly. Returns the created person ID.
update_personUpdate fields on an existing person. Only provided fields are modified.
delete_personPermanently delete a person from Huly. This action cannot be undone.
list_employeesList employees (persons who are team members). Returns employees sorted by modification date (newest first).
list_organizationsList all organizations in the Huly workspace. Returns organizations sorted by modification date (newest first).
create_organizationCreate a new organization in Huly. Optionally add members by person ID or email. Returns the created organization ID.
preview_deletionPreview the impact of deleting a Huly entity before actually deleting it. Shows affected sub-entities, relations, and warnings. Supports issues, projects, components, and milestones. Use this to understand cascade effects before calling a delete operation.
list_teamspacesList all Huly document teamspaces. Returns teamspaces sorted by name. Supports filtering by archived status.
get_teamspaceGet details of a single Huly teamspace by name or ID. Returns teamspace metadata including name, description, archived and private status.
create_teamspaceCreate a new Huly document teamspace. Returns the created teamspace id and name.
update_teamspaceUpdate fields on an existing Huly teamspace. Only provided fields are modified.
delete_teamspacePermanently delete a Huly teamspace and all its documents. This action cannot be undone.
list_documentsList documents in a Huly teamspace. Returns documents sorted by modification date (newest first). Supports searching by title substring (titleSearch) and content (contentSearch).
get_documentRetrieve full details for a Huly document including markdown content. Use this to view document content and metadata.
create_documentCreate a new document in a Huly teamspace. Content supports markdown formatting. Returns the created document id.
update_documentUpdate fields on an existing Huly document. Only provided fields are modified. Content updates support markdown.
delete_documentPermanently delete a Huly document. This action cannot be undone.
list_issuesQuery Huly issues with optional filters. Returns issues sorted by modification date (newest first). Supports filtering by project, status, assignee, and milestone. Supports searching by title substring (titleSearch) and description content (descriptionSearch).
get_issueRetrieve full details for a Huly issue including markdown description. Use this to view issue content, comments, or full metadata.
create_issueCreate a new issue in a Huly project. Optionally create as a sub-issue by specifying parentIssue. Description supports markdown formatting. Returns the created issue identifier.
update_issueUpdate fields on an existing Huly issue. Only provided fields are modified. Description updates support markdown.
add_issue_labelAdd a tag/label to a Huly issue. Creates the tag if it doesn't exist in the project.
remove_issue_labelRemove a tag/label from a Huly issue. Detaches the label reference; does not delete the label definition.
delete_issuePermanently delete a Huly issue. This action cannot be undone.
list_componentsList components in a Huly project. Components organize issues by area/feature. Returns components sorted by modification date (newest first).
get_componentRetrieve full details for a Huly component. Use this to view component content and metadata.
create_componentCreate a new component in a Huly project. Components help organize issues by area/feature. Returns the created component ID and label.
update_componentUpdate fields on an existing Huly component. Only provided fields are modified.
set_issue_componentSet or clear the component on a Huly issue. Pass null for component to clear it.
delete_componentPermanently delete a Huly component. This action cannot be undone.
list_issue_templatesList issue templates in a Huly project. Templates define reusable issue configurations. Returns templates sorted by modification date (newest first).
get_issue_templateRetrieve full details for a Huly issue template. Use this to view template content and default values.
create_issue_templateCreate a new issue template in a Huly project. Templates define default values for new issues. Returns the created template ID and title.
create_issue_from_templateCreate a new issue from a template. Applies template defaults, allowing overrides for specific fields. Returns the created issue identifier.
update_issue_templateUpdate fields on an existing Huly issue template. Only provided fields are modified.
delete_issue_templatePermanently delete a Huly issue template. This action cannot be undone.
add_issue_relationAdd a relation between two issues. Relation types: 'blocks' (source blocks target — pushes into target's blockedBy), 'is-blocked-by' (source is blocked by target — pushes into source's blockedBy), 'relates-to' (bidirectional link — updates both sides). targetIssue accepts cross-project identifiers l…
remove_issue_relationRemove a relation between two issues. Mirrors add_issue_relation: 'blocks' pulls from target's blockedBy, 'is-blocked-by' pulls from source's blockedBy, 'relates-to' pulls from both sides. No-op if the relation doesn't exist.
list_issue_relationsList all relations of an issue. Returns blockedBy (issues blocking this one) and relations (bidirectional links) with resolved identifiers. Does NOT return issues that this issue blocks — use list_issue_relations on the target issue to see that.
list_labelsList label/tag definitions in the workspace. Labels are global (not project-scoped). Returns labels for tracker issues sorted by modification date (newest first).
create_labelCreate a new label/tag definition in the workspace. Labels are global and can be attached to any issue. Returns existing label if one with the same title already exists (created=false). Use add_issue_label to attach a label to a specific issue.
update_labelUpdate a label/tag definition. Accepts label ID or title. Only provided fields are modified.
delete_labelPermanently delete a label/tag definition. Accepts label ID or title. This action cannot be undone.
list_milestonesList milestones in a Huly project. Returns milestones sorted by modification date (newest first).
get_milestoneRetrieve full details for a Huly milestone. Use this to view milestone content and metadata.
create_milestoneCreate a new milestone in a Huly project. Returns the created milestone ID and label.
update_milestoneUpdate fields on an existing Huly milestone. Only provided fields are modified.
set_issue_milestoneSet or clear the milestone on a Huly issue. Pass null for milestone to clear it.
delete_milestonePermanently delete a Huly milestone. This action cannot be undone.
list_notificationsList inbox notifications. Returns notifications sorted by modification date (newest first). Supports filtering by read/archived status.
get_notificationRetrieve full details for a notification. Use this to view notification content and metadata.
64 further tools are not listed here. The complete surface is in the source.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
Effect `AsyncLocalStorage` context lost/contaminated inside Effect fibers under concurrent load with RPC
ws: Memory exhaustion DoS from tiny fragments and data chunks
ws: Uninitialized memory disclosure
HULY_TOKENAuth API token (alternative to email/password)Tool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
164/164 tools missing one or more hints — list_activity (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); add_reaction (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); remove_reaction (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +161 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tool test coverage
Only 1/164 tools referenced in tests (1%)
Write tests that reference each tool by name so every tool has at least one test.
Shell command execution
1 child_process call — runs shell commands
Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.
Production dependencies are patched
0 critical, 3 high severity in production deps — @modelcontextprotocol/sdk@1.0.4 (high), effect@3.19.15 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/spatialy/huly-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check