@jtmeunier87/teamwork-mcp
npm
v1.5.4
Published by @jtmeunier87 — no publish provenance, so origin is unverified, but the source is public: the repository link below is self-declared yet readable, so you can inspect the code before adopting it.
MCP server for the Teamwork.com REST API — full project management control via Model Context Protocol
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 4 = 96. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −1 | publisher verification (public source) — no provenance, but the source is public and inspectable |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Tool "tw_delete_file" can write, overwrite or delete files (keyword "delete_file" in tool name). Verify it is scoped to a safe directory.
Fix: Constrain file operations to an explicit, non-sensitive root; reject path traversal.
Location: tool tw_delete_file
Tool "tw_delete_file" can mutate/egress but declares no destructiveHint. Clients that don't default to spec-safe behavior may not prompt before running it.
Fix: Declare accurate annotations, and gate destructive tools on user confirmation regardless.
Location: tool tw_delete_file
Each tool and what it can reach — statically extracted from the published source.
tw_create_webhooknetwork egresstw_delete_filewrites filestw_delete_webhooknetwork egresstw_add_people_to_projectno sensitive capabilitytw_complete_milestoneno sensitive capabilitytw_complete_taskno sensitive capabilitytw_create_companyno sensitive capabilitytw_create_linkno sensitive capabilitytw_create_messageno sensitive capabilitytw_create_milestoneno sensitive capabilitytw_create_notebookno sensitive capabilitytw_create_projectno sensitive capabilitytw_create_project_commentno sensitive capabilitytw_create_riskno sensitive capabilitytw_create_subtaskno sensitive capabilitytw_create_tagno sensitive capabilitytw_create_taskno sensitive capabilitytw_create_task_commentno sensitive capabilitytw_create_tasklistno sensitive capabilitytw_delete_companyno sensitive capabilitytw_delete_milestoneno sensitive capabilitytw_delete_notebookno sensitive capabilitytw_delete_personno sensitive capabilitytw_delete_projectno sensitive capabilitytw_delete_tagno sensitive capabilitytw_delete_taskno sensitive capabilitytw_delete_tasklistno sensitive capabilitytw_delete_time_entryno sensitive capabilitytw_get_accountno sensitive capabilitytw_get_calendar_eventsno sensitive capabilitytw_get_companiesno sensitive capabilitytw_get_company_by_idno sensitive capabilitytw_get_custom_fields_by_projectno sensitive capabilitytw_get_dependentsno sensitive capabilitytw_get_expensesno sensitive capabilitytw_get_file_by_idno sensitive capabilitytw_get_files_by_projectno sensitive capabilitytw_get_job_rolesno sensitive capabilitytw_get_links_by_projectno sensitive capabilitytw_get_meno sensitive capabilitytw_get_message_by_idno sensitive capabilitytw_get_messagesno sensitive capabilitytw_get_messages_by_projectno sensitive capabilitytw_get_milestonesno sensitive capabilitytw_get_milestones_by_projectno sensitive capabilitytw_get_notebook_by_idno sensitive capabilitytw_get_notebooksno sensitive capabilitytw_get_notebooks_by_projectno sensitive capabilitytw_get_peopleno sensitive capabilitytw_get_person_by_idno sensitive capabilitytw_get_predecessorsno sensitive capabilitytw_get_project_by_idno sensitive capabilitytw_get_project_categoriesno sensitive capabilitytw_get_project_commentsno sensitive capabilitytw_get_project_peopleno sensitive capabilitytw_get_projectsno sensitive capabilitytw_get_risksno sensitive capabilitytw_get_risks_by_projectno sensitive capabilitytw_get_subtasksno sensitive capabilitytw_get_tagsno sensitive capabilitytw_get_task_by_idno sensitive capabilitytw_get_task_commentsno sensitive capabilitytw_get_task_metrics_completeno sensitive capabilitytw_get_task_metrics_lateno sensitive capabilitytw_get_tasklistsno sensitive capabilitytw_get_tasklists_by_projectno sensitive capabilitytw_get_tasksno sensitive capabilitytw_get_tasks_by_projectno sensitive capabilitytw_get_tasks_by_tasklistno sensitive capabilitytw_get_time_entriesno sensitive capabilitytw_get_time_entries_by_projectno sensitive capabilitytw_get_time_entries_by_taskno sensitive capabilitytw_get_timersno sensitive capabilitytw_get_timezonesno sensitive capabilitytw_get_webhooksno sensitive capabilitytw_get_workflow_stagesno sensitive capabilitytw_log_timeno sensitive capabilitytw_move_task_to_stageno sensitive capabilitytw_rate_limit_statusno sensitive capabilitytw_reassign_taskno sensitive capabilitytw_set_predecessorsno sensitive capabilitytw_tag_taskno sensitive capabilitytw_uncomplete_taskno sensitive capabilitytw_untag_taskno sensitive capabilitytw_update_companyno sensitive capabilitytw_update_milestoneno sensitive capabilitytw_update_notebookno sensitive capabilitytw_update_personno sensitive capabilitytw_update_projectno sensitive capabilitytw_update_tagno sensitive capabilitytw_update_taskno sensitive capabilitytw_update_time_entryno sensitive capabilityScan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v1.5.4 latest |
A 96/100 | 2 | 1.12.1 | 2026-07-28 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan @jtmeunier87/teamwork-mcp --online
Independent packages implementing the same tool, scanned with the same engine. Compare all 2 side by side →
Free public tax reference data — GST/VAT, income, company and capital-gains tax rules for 50+ countries.
The approval gate for unattended UCP buying agents — a policy/approval MCP proxy in front of a merchant's UCP checkout endpoint.
Autotask PSA MCP server. Generic entity query/get/create/update across the full REST API plus convenience tools for tickets, companies, contacts, projects, tasks and time entries. AI-safe with readonly mode and destructive-action confirmation. stdio + opt
MCP server for B2C Commerce developer experience tools
Search, compare and contact real-world companies through a public MCP business directory.
Norwegian business register (Brønnøysundregistrene) as an MCP server — companies, roles, subunits and annual accounts, with the register's silent traps encoded as guards.