About
WEEEK tasks by name, not IDs — an MCP server
Security Report
This is a well-structured MCP server for WEEEK task management with solid security practices. Authentication is properly required for API calls, sensitive operations like file attachment and deletion are guarded with appropriate restrictions, and the codebase shows good input validation and error handling. Minor code quality observations exist around broad error catching and logging, but these do not constitute security vulnerabilities. Supply chain analysis found 5 known vulnerabilities in dependencies (2 critical, 2 high severity). Package verification found 1 issue.
7 files analyzed · 10 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
What You'll Need
Set these up before or after installing:
Environment variable: WEEEK_API_TOKEN
Environment variable: WEEEK_API_BASE_URL
Environment variable: WEEEK_TIMEOUT_MS
Environment variable: WEEEK_ATTACH_DIR
Environment variable: WEEEK_ATTACH_MAX_BYTES
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-ilyaivanchikov-weeek-mcp-smart": {
"env": {
"WEEEK_API_TOKEN": "your-weeek-api-token-here",
"WEEEK_ATTACH_DIR": "your-weeek-attach-dir-here",
"WEEEK_TIMEOUT_MS": "your-weeek-timeout-ms-here",
"WEEEK_API_BASE_URL": "your-weeek-api-base-url-here",
"WEEEK_ATTACH_MAX_BYTES": "your-weeek-attach-max-bytes-here"
},
"args": [
"-y",
"weeek-mcp-smart"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
weeek-mcp-smart
The only one-click WEEEK MCP server — it takes names, not IDs. Create a task in one call:
weeek_create_task({ title: "Ship v1", project: "Marketing",
column: "In Progress", assignee: "Ilya", due: "next friday" })
No list_projects → list_boards → list_columns → list_members dance first.
Install (Claude Code / Cursor)
claude mcp add weeek -s user -- npx -y weeek-mcp-smart
# then set WEEEK_API_TOKEN in the generated config
Install (Claude Desktop, one click)
⬇ Download the latest .mcpb, then open it in Claude Desktop (Settings → Extensions → install from file). You'll be prompted for your WEEEK API token — it's stored in your OS keychain.
All releases: https://github.com/IlyaIvanchikov/weeek-mcp/releases
Get a token
WEEEK → Settings → API → generate a personal token.
Configuration
| Env var | Required | Default | Purpose |
|---|---|---|---|
WEEEK_API_TOKEN | to call tools | — | Your WEEEK personal API token. The server starts and lists its tools without it, but any tool call fails until it is set. |
WEEEK_API_BASE_URL | no | https://api.weeek.net/public/v1 | Override for self-hosted / regional hosts. |
WEEEK_TIMEOUT_MS | no | 30000 | Per-request timeout. |
WEEEK_ATTACH_DIR | no | the server's working directory | Directory weeek_attach_file may read from (see Safety). |
WEEEK_ATTACH_MAX_BYTES | no | 10485760 (10 MB) | Max attachable file size. |
Safety
This server is driven by an LLM that can read untrusted content (task text, web pages), so the two riskiest tools are guarded:
weeek_attach_fileonly reads files inside an allowed directory (its subfolders included). By default that's the server's working directory — so it works with no setup for local files, while paths outside it (/etc/passwd,~/.ssh,..traversal, symlinks that escape) are refused. SetWEEEK_ATTACH_DIRto point the jail somewhere specific or lock it down further. No special folder is required.weeek_delete_taskis permanent and requires an explicitconfirm: true; to merely close a task useweeek_complete_task.
Tools
Reads: weeek_version, weeek_list_projects, weeek_list_tasks, weeek_get_task.
Writes: weeek_create_task, weeek_create_tasks, weeek_update_task, weeek_move_task, weeek_complete_task, weeek_attach_file, weeek_delete_task.
Author
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
