Back to Home
avinashsingh icon

mcp-sdlc-tracker

Verified Safe

by avinashsingh

Overview

Provides a Model Context Protocol (MCP) server for SQLite-based task and project tracking with full SDLC entity, wiki, and comments management.

Installation

Run Command
npm start

Security Notes

SQL injection risks are largely mitigated by `better-sqlite3`'s consistent use of parameterized queries throughout the server. The `tools/write-full-file.ts` tool allows writing to arbitrary file paths within the initialized project directory, posing a moderate risk for an AI agent capable of arbitrary file write operations, though backups are created. The `tools/kg.ts` utilizes `child_process.execSync` but with hardcoded and well-defined `find` commands, limiting direct RCE from user input originating from client requests.

Similar Servers

Stats

Interest Score31
Security Score8
Cost ClassMedium
Avg Tokens700
Stars1
Forks0
Last Update2025-12-09

Tags

mcpsqlitetrackertasksprojectsSDLCworkflow