Kaiten MCP (tyunn/kaiten-mcp) is an MCP server listed on the M8ven Trust Index. It scores 56 out of 100, grade D. It declares 39 tools. No publisher has claimed this listing.
MCP server and CLI tool for interacting with Kaiten project management API, optimized for token efficiency. Enables AI assistants to search, create, update, and manage tasks with minimal token usage.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
tyunn
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
kaiten_spacesGet list of available Kaiten spaces
kaiten_boardsGet list of boards in a space
kaiten_columnsGet list of columns in a board
kaiten_cardsGet list of cards (optimized format)
kaiten_cardGet card details
kaiten_create_cardCreate a new independent card on a board. Use this for creating separate tasks, not child cards/subtasks. Если известен laneId — указывайте, иначе карточка попадёт на дефолтную lane доски, что для многих досок неверно.
kaiten_update_cardUpdate a card
kaiten_delete_cardDelete a card
kaiten_move_cardMove a card to different column. Если laneId не указан, карточка останется на текущей lane (или дефолтной для новой колонки).
kaiten_assign_cardAssign user to card
kaiten_find_cardsFind cards by tag (token optimized - returns only id, title, board_id, column_id, tags)
kaiten_add_commentAdd comment to card
kaiten_get_commentsGet comments for card
kaiten_create_child_cardCreate a child card under a parent card. Use this when you need to create a nested task, subtask, or child card.
kaiten_get_child_cardsGet immediate child cards of a parent card (one level only)
kaiten_get_all_child_cardsGet all child cards of a parent card recursively (includes nested child cards at all levels)
kaiten_get_parentGet the parent card of a child card/subtask
kaiten_attach_to_parentLink an existing card as a child/subtask under a parent card. Use this when you already have a card that needs to become a subtask of another card.
kaiten_detach_from_parentRemove parent-child relationship - makes a subtask/child card into an independent card
kaiten_add_tagAdd tag to card
kaiten_remove_tagRemove tag from card
kaiten_git_branchCreate git branch for card
kaiten_git_checkoutCheckout git branch for card
kaiten_git_commitCommit changes with card reference
kaiten_git_statusGet git status
kaiten_git_pushPush git branch for card
kaiten_usersGet list of users
kaiten_search_usersSearch users by query
kaiten_get_checklistsGet checklists from a card
kaiten_create_checklistCreate a checklist on a card
kaiten_delete_checklistDelete a checklist from a card
kaiten_update_checklistUpdate a checklist name
kaiten_toggle_checklist_itemCheck or uncheck a checklist item
kaiten_add_checklist_itemAdd an item to a checklist
kaiten_delete_checklist_itemDelete an item from a checklist
kaiten_get_filesGet list of files attached to a card
kaiten_download_fileDownload a single file from a card to temp directory
kaiten_download_all_filesDownload all files from a card to temp directory
kaiten_clean_tempClean temporary directory for Kaiten files
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Axios: Header Injection via Prototype Pollution
Allocation of Resources Without Limits or Throttling in Axios
KAITEN_TEMP_DIR/tmp/kaitenTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
39/39 tools missing one or more hints — kaiten_spaces (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); kaiten_boards (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); kaiten_columns (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +36 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
License file
No license file
Add a LICENSE file (MIT, Apache-2.0, etc.).
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 11 high severity in production deps — axios@1.12.2 (high), axios@1.12.2 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/tyunn/kaiten-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check