mcp-server-tapd
PyPI
v8.0.81
Published by an unidentified publisher — no publish provenance and no public repository, so the publisher could not be verified and the source cannot be independently located.
TAPD MCP Server
The grade answers one question — how safe is this server for you to adopt — so it is computed in two auditable stages. Nothing below is an opinion or an LLM's guess; every line is a real term the deterministic engine applied, and the same input always yields the same number.
1. Threat score — 100 − 0 = 100. What the published surface and source actually contain:
The deterministic scan raised no scored threat in the surface it inspected — the threat score stayed at 100. Capability observations and advisory notes are recorded but never lower it.
2. Client adoption risk — 100 − 5 = 95. Three small, subtract-only factors that reflect your risk in adopting it — a clean scan proves less on a powerful, unverified or barely-inspectable package, so the grade says so plainly:
| Points | Adoption-risk factor |
|---|---|
| −3 | capability blast radius (moderate) — client exposure if the model is manipulated |
| −2 | publisher verification (unlinked) — no provenance/repo link, but the shipped source was fully read |
Capability observations and info notes are shown under Findings but never scored.
Open any row's finding below for the file, line and evidence behind a deduction.
Untrusted-input tools ([get_image, get_entity_attachments]) co-exist with external-action tools ([create_comments]). A prompt injection could cause unwanted external actions, though no direct sensitive-data leak path was found.
Evidence: untrusted [get_image, get_entity_attachments] → sinks [create_comments]
Fix: Require confirmation for state-changing/egress actions triggered after processing untrusted content.
Location: flow get_image → create_comments
Each tool and what it can reach — statically extracted from the published source.
create_commentsnetwork egressget_entity_attachmentsingests untrusted inputget_imageingests untrusted inputadd_timesheetsno sensitive capabilitycreate_bugno sensitive capabilitycreate_iterationno sensitive capabilitycreate_or_update_tcasesno sensitive capabilitycreate_story_or_taskno sensitive capabilitycreate_tcases_batchno sensitive capabilitycreate_wikino sensitive capabilityentity_relationsno sensitive capabilityget_bugno sensitive capabilityget_bug_countno sensitive capabilityget_commentsno sensitive capabilityget_commit_msgno sensitive capabilityget_entity_custom_fieldsno sensitive capabilityget_entity_relationsno sensitive capabilityget_iterationsno sensitive capabilityget_related_bugsno sensitive capabilityget_release_infono sensitive capabilityget_stories_fields_infono sensitive capabilityget_stories_fields_lableno sensitive capabilityget_stories_or_tasksno sensitive capabilityget_story_or_task_countno sensitive capabilityget_sub_workspacesno sensitive capabilityget_tcasesno sensitive capabilityget_timesheetsno sensitive capabilityget_todono sensitive capabilityget_user_participant_projectsno sensitive capabilityget_wikino sensitive capabilityget_workflows_all_transitionsno sensitive capabilityget_workflows_last_stepsno sensitive capabilityget_workflows_status_mapno sensitive capabilityget_workitem_typesno sensitive capabilityget_workspace_infono sensitive capabilityget_workspace_usersno sensitive capabilityprogram_bind_entitiesno sensitive capabilitysend_qiwei_messageno sensitive capabilityupdate_bugno sensitive capabilityupdate_commentsno sensitive capabilityupdate_iterationno sensitive capabilityupdate_story_or_taskno sensitive capabilityupdate_timesheetsno sensitive capabilityupdate_wikino sensitive capabilityCross-tool combinations that form a data-exfiltration primitive (untrusted input → sensitive source → external sink).
Scan history per published version. The engine is deterministic — the same version always yields the same score, so a changed score means the package itself changed.
| Version | Score | Findings | Engine | Scanned |
|---|---|---|---|---|
v8.0.81 latest |
A 95/100 | 1 | 1.13.0 | 2026-08-25 |
v8.0.80 |
A 95/100 | 1 | 1.12.1 | 2026-07-31 |
v8.0.79 |
A 95/100 | 1 | 1.12.1 | 2026-07-27 |
Show this server's live Trust Score in your README, docs or website. The badge is served straight from the registry and updates automatically after every rescan — no API key needed. It links back to this page, so anyone who sees the grade can also read the findings behind it instead of taking a number on faith.
The score above is reproducible: the same package version always yields the same result. Run it locally or over the free API — no account, no LLM, fully deterministic.
npx mcptrustchecker scan mcp-server-tapd --online --registry pypi
Independent packages implementing the same tool, scanned with the same engine. Compare all 3 side by side →
MCP server for TAPD project management API, enabling AI assistants to manage stories, bugs, tasks, iterations and more via natural language
TAPD MCP Server - 在 Cursor/Copilot 中查询、分析和回填 TAPD bug / 需求
MCP AgentChat - 让 AI Agent 通过 Telegram 与用户实时交互:发送消息、图片,等待用户回复
A Model Context Protocol (MCP) server for Airthings Air Quality Monitor devices.
MCP server for Anki
TypeScript package for reading and searching Apple Notes on macOS via direct SQLite access. Includes markdown conversion, attachment support, and offers a local MCP server!
Verified biotech catalyst calendar (PDUFA/AdComm/trial readouts) anchored to official sources.
Appointment booking platform letting agents check provider availability and create bookings.