Back to Home
aosyang icon

TaskMCP

Verified Safe

by aosyang

Overview

A multi-workspace task management system enabling hierarchical organization, real-time synchronization, and AI Agent interaction via an MCP server for natural language task operations.

Installation

Run Command
python app.py

Security Notes

The Flask `SECRET_KEY` is hardcoded (`'task-secret-key'`) in `app.py`, which is a critical security vulnerability for any deployment beyond local development, as it allows session hijacking and other attacks. The `update_task_comments_from_file` MCP tool in `mcp_server.py` allows reading content from an arbitrary `file_path` on the server if the AI agent or a malicious user can control this parameter, posing a risk of local file disclosure. However, SQL injection is prevented through parameterized queries, and XSS is mitigated on the frontend using DOMPurify with strict configurations for markdown rendering. The option to bind to `0.0.0.0` for network access is documented.

Similar Servers

Stats

Interest Score0
Security Score5
Cost ClassLow
Avg Tokens200
Stars0
Forks1
Last Update2026-01-17

Tags

Task ManagementHierarchical TasksReal-time SyncAI AgentMulti-workspace