# Granoflow (npm · @granoflow/mcp-server)

Connect MCP-capable AI agents to local Granoflow tasks, reviews, cards, imports, and work memory.

- Trust score: 56/100 (low)
- Change this week: +13
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-03

## Components

- npm · `@granoflow/mcp-server`: 56/100 (this document), [markdown](https://verifymcp.io/servers/com-granoflow-mcp-server/granoflow-mcp-server.md), [page](https://verifymcp.io/servers/com-granoflow-mcp-server/granoflow-mcp-server)

## Channel facts

- Registry: `npm`
- Package: `@granoflow/mcp-server`
- Version: `0.1.16`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-03.

- **Supply Chain Security**: 87/100
  - No malware found by supply-chain analysis.
  - Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.
  - No install/post-install scripts declared.
  - Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 5 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 40/100
  - AI-judged instruction clarity (poor).
  - Tool/resource definitions use about 9272 tokens (~71/item across 129 items; 129 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 74/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 22% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### Claude

```bash
claude mcp add com-granoflow-mcp-server -- npx -y @granoflow/mcp-server
```

### Codex

```bash
codex mcp add com-granoflow-mcp-server -- npx -y @granoflow/mcp-server
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-granoflow-mcp-server": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@granoflow/mcp-server"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-granoflow-mcp-server --command npx --arg -y --arg @granoflow/mcp-server
```

### Hermes

```yaml
mcp_servers:
  com-granoflow-mcp-server:
    command: "npx"
    args: ["-y", "@granoflow/mcp-server"]
```

### Other

```json
{
  "mcpServers": {
    "com-granoflow-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@granoflow/mcp-server"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-03 (score 56, +7)

- [security improvement] Known CVEs: unverified → partial
- [functional improvement] Schema quality: unverified → poor

### 2026-08-02 (score 49, +29)

- [security regression] Provenance: unverified → fail
- [security improvement] Install scripts: unverified → pass
- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] License: unverified → pass
- [functional improvement] Dependency health: unverified → partial
- [functional improvement] Maintenance: unverified → pass
- [functional improvement] MCP protocol: unverified → pass
- [functional] Licence: MIT

### 2026-08-01 (score 20, −5)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-07-31 (score 25, −18)

- [security regression] Malware scan: pass → unverified

### 2026-07-29 (score 43, +19)

- [functional improvement] Tool coverage: unverified → 100

### 2026-07-28 (score 24, −19)

- [functional regression] Tool coverage: 100 → unverified
- [functional] First check of Schema quality: unverified

### 2026-07-27 (score 43)

First indexed and scored.

## MCP tools (129)

### `granoflow_agent_workflow_skill` (~216 tokens)

Read the bundled Granoflow Agent Workflow skill. Call this when a user works with Granoflow tasks, says 'Analyze the first task', says 'Start the first task', says 'Create a task from this requirement', says 'Process today's tasks', asks in their own language to analyze/start one selected task, create a task from a discussed requirement, or process tasks for a date/range/all-task scope, needs approval or missing information recorded in a task, finishes tasks, asks for weekly or monthly reviews, task reviews, review cards, historical context, decisions, lessons, similar past work, or long-term work memory, or politely/strongly signals that Granoflow/MCP/generated agent output is wrong or misaligned. Use granoflow_daily_review_skill for an explicitly requested daily review or mood/efficiency note, and granoflow_first_run_import_skill for first-run import from Cursor, Codex, Hermes, or other agents. Do not call it for unrelated venting or unrelated disagreement.

### `granoflow_daily_review_skill` (~73 tokens)

Read the bundled Granoflow Daily Review skill. Call this when a user explicitly asks to review, summarize, or journal one day, including mood or efficiency notes. It requires display of evidence and a draft, conversation and explicit confirmation, then write and App/API readback of only approved daily-review fields.

### `granoflow_first_run_import_skill` (~111 tokens)

Read the bundled Granoflow First-Run Import skill. Call this when a user says 'Initialize Granoflow', optionally asks to import data, or uses an equivalent request in their own language. The workflow checks the connection, offers all unavailable recommended AI capability collections using only their names and plain-language functions, and previews authorized Cursor, Codex, Hermes, or other agent records as projects, monthly milestones, tasks, review-card candidates, and context backfills before any requested import write.

### `granoflow_review_card_draft_skill` (~70 tokens)

Read the bundled core Granoflow review-card authoring skill. Call it for every lifecycle Card Checkpoint and every card search, link, create, or modification so similarity fallback, AI filtering, note quality, preview, approval, controlled writes, and readback use one workflow.

### `granoflow_gfmcp_runner_skill` (~48 tokens)

Read the bundled GFMCP automatic task runner skill. Use it to install, operate, or diagnose the optional five-minute Python worker for pending tasks tagged GFMCP.

### `granoflow_delegated_authorization_skill` (~67 tokens)

Read the bundled Granoflow Delegated Authorization skill. Use it when a user wants bounded unattended continuation or when a Task Work phase gate may consume a confirmed, current authorization envelope. The skill and its validator never infer consent from tags, urgency, or absence.

### `granoflow_task_orchestrator_skill` (~85 tokens)

Read the bundled context-aware Granoflow Task Orchestrator. Use it as the single upper-layer entrypoint when natural language or gf shortcuts may mean quick capture, context enrichment, Analysis, Planning, end-to-end local-safe execution, or completion audit. It delegates every phase to the existing workflow owners and never turns inferred intent into external or destructive authorization.

### `granoflow_milestone_workflow_skill` (~79 tokens)

Read the bundled Granoflow Milestone Workflow skill. Use it when one delegated outcome spans multiple child tasks and needs a stable milestone charter, evolving task portfolio, dependency and handoff coordination, bounded authorization, replanning, cross-task integration evidence, and milestone-level acceptance before closure. Child implementation remains owned by Task Work.

### `granoflow_persistent_milestone_runner_skill` (~78 tokens)

Read the bundled provider-neutral Granoflow Persistent Milestone Runner skill. Use it for restart-safe milestone execution with leases, heartbeat, bounded attempt history, no-progress replanning, resumable interaction nodes, explicit authorization manifests, and evidence-gated completion. A separate user Skill may choose the worker command or model.

### `granoflow_project_definition_skill` (~57 tokens)

Read the bundled Granoflow Project Definition skill. Use it to build or refine one Project Work YAML step by step or from a vague request, then gate manual and automatic project actions through App-owned readiness and artifact readback.

### `granoflow_bundled_skill_reference` (~86 tokens)

Read one public Markdown reference from a bundled Granoflow skill. Discover valid referenceId values from that skill's references manifest first. This read-only package operation does not call the Granoflow Local HTTP API or require an API token.

Input parameters:

- `referenceId` (string, required): Reference identifier from the selected skill's references manifest.
- `skillId` (string, required)

### `granoflow_gfmcp_prepare` (~49 tokens)

Create or repair the GFMCP custom tag and its app-localized task description template. Granoflow owns localization and idempotency.

Input parameters:

- `dryRun` (boolean)

### `granoflow_gfmcp_safe_sync` (~55 tokens)

Ask the Granoflow app to perform a safe pre-poll sync only when current authorization permits it. Defaults to dry-run and never guesses membership or key state.

Input parameters:

- `dryRun` (boolean)

### `granoflow_gfmcp_candidates` (~39 tokens)

List pending Granoflow tasks tagged GFMCP. The tag marks eligibility but does not grant authorization for privileged or external actions.

### `granoflow_setup_status` (~26 tokens)

Inspect Granoflow MCP config and Local HTTP API health without printing secrets.

### `granoflow_setup_detect_local_api` (~49 tokens)

Probe a bounded localhost port list for Granoflow identity. This never scans all ports or writes config.

Input parameters:

- `ports` (array)
- `timeoutMs` (integer)

### `granoflow_setup_write_config` (~70 tokens)

Preview or write one user-confirmed MCP-owned non-secret Granoflow API URL or local port. Defaults to dry-run; writes are reread and verified immediately.

Input parameters:

- `apiBaseUrl` (string)
- `apiPort` (integer)
- `dryRun` (boolean)

### `granoflow_setup_open_config` (~43 tokens)

Create and optionally open the MCP-owned non-secret Granoflow config file.

Input parameters:

- `createIfMissing` (boolean)
- `open` (boolean)

### `granoflow_setup_open_app` (~103 tokens)

Preview or open the installed Granoflow app after user approval. Uses a cross-process launch lease for real opens, and refuses if another MCP launch is in progress, any Granoflow process is already running, or process state cannot be verified, even when the configured Local HTTP API URL or port is unreachable. Defaults to dry-run.

Input parameters:

- `appName` (string)
- `appPath` (string)
- `dryRun` (boolean)

### `granoflow_health` (~22 tokens)

Check whether the Granoflow Local HTTP API is reachable.

### `granoflow_version` (~22 tokens)

Show Granoflow app and Local HTTP API version metadata.

### `granoflow_capabilities` (~22 tokens)

List capabilities exposed by the running Granoflow app.

### `granoflow_ai_agent_tools` (~44 tokens)

List Granoflow AI-agent tool contracts from the running app. Use with granoflow_agent_workflow_skill for task, review, and memory-style questions.

### `granoflow_agent_preferences_get` (~74 tokens)

Resolve compact Agent preferences from project YAML, MCP-local defaults, and newcomer-safe defaults. Project values win field by field. This read never grants push, publish, deploy, deletion, login, secret access, or destructive Git actions.

Input parameters:

- `dryRun` (boolean)
- `projectId` (string)

### `granoflow_agent_preferences_write_defaults` (~59 tokens)

Preview or write non-secret MCP-local Agent defaults. Per-project overrides remain in project_rules.yaml. Defaults to dry-run and returns a redacted readback.

Input parameters:

- `dryRun` (boolean)
- `preferences` (object, required)

### `granoflow_git_missing_notice_record` (~56 tokens)

Record that the one-time newcomer Git-unavailable notice was shown. This stores only a boolean marker and never installs Git or changes a repository.

Input parameters:

- `dryRun` (boolean)
- `shown` (boolean)

### `granoflow_evidence_list` (~34 tokens)

List Evidence owned by one task, including source status and internal links.

Input parameters:

- `taskId` (string, required)

### `granoflow_evidence_search` (~42 tokens)

Search the independent Evidence lane. The app reports vector or explicit degraded fallback status.

Input parameters:

- `limit` (integer)
- `query` (string, required)

### `granoflow_evidence_get` (~32 tokens)

Get one Evidence item with its task ownership and internal link.

Input parameters:

- `evidenceId` (string, required)

### `granoflow_evidence_authoring_preview` (~40 tokens)

Preview Evidence candidates for a reviewed task with zero writes.

Input parameters:

- `candidates` (array, required)
- `taskId` (string, required)

### `granoflow_evidence_authoring_apply` (~93 tokens)

Apply only user-approved Evidence operations from a current preview and return App readback.

Input parameters:

- `approvedOperationIds` (array, required)
- `expectedTaskReviewHash` (string, required)
- `expectedTaskReviewRevision` (integer, required)
- `idempotencyKey` (string, required)
- `previewHash` (string, required)
- `previewToken` (string, required)
- `taskId` (string, required)

### `granoflow_evidence_update` (~43 tokens)

Edit existing Evidence with optimistic revision checking.

Input parameters:

- `evidenceId` (string, required)
- `expectedRevision` (integer, required)
- `statement` (string, required)

### `granoflow_evidence_delete` (~52 tokens)

Delete existing Evidence after explicit confirmation. This does not run during sync or backup restore.

Input parameters:

- `confirmed` (boolean, required)
- `evidenceId` (string, required)
- `expectedRevision` (integer, required)

### `granoflow_experience_list` (~59 tokens)

List independent Experience records, optionally for a daily, weekly, or monthly review scope.

Input parameters:

- `limit` (integer)
- `offset` (integer)
- `periodKind` (string)
- `scopeId` (string)

### `granoflow_experience_get` (~36 tokens)

Get one Experience with provenance, task usages, Knowledge links, and merge redirect.

Input parameters:

- `experienceId` (string, required)

### `granoflow_project_experiences` (~32 tokens)

List independent Experience records derived from tasks in one project.

Input parameters:

- `projectId` (string, required)

### `granoflow_milestone_experiences` (~34 tokens)

List independent Experience records derived from tasks in one milestone.

Input parameters:

- `milestoneId` (string, required)

### `granoflow_experience_search` (~39 tokens)

Search the independent Experience lane with explicit vector or degraded fallback status.

Input parameters:

- `limit` (integer)
- `query` (string, required)

### `granoflow_experience_authoring_preview` (~51 tokens)

Preview Experience distillation for a task or periodic review with zero writes.

Input parameters:

- `candidates` (array, required)
- `scopeId` (string, required)
- `scopeType` (string, required)

### `granoflow_experience_authoring_apply` (~60 tokens)

Apply only user-approved Experience operations from a current preview.

Input parameters:

- `approvedOperationIds` (array, required)
- `idempotencyKey` (string, required)
- `previewHash` (string, required)
- `previewToken` (string, required)

### `granoflow_experience_update` (~77 tokens)

Edit all required fields of an independent Experience with optimistic revision checking.

Input parameters:

- `boundary` (string, required)
- `conclusion` (string, required)
- `context` (string, required)
- `expectedRevision` (integer, required)
- `experienceId` (string, required)
- `nextAction` (string, required)
- `rationale` (string, required)

### `granoflow_experience_delete_impact` (~35 tokens)

Preview the full impact of permanently deleting an Experience with zero writes.

Input parameters:

- `experienceId` (string, required)

### `granoflow_experience_delete` (~67 tokens)

Permanently delete an Experience and all relations after both impact and final confirmation.

Input parameters:

- `expectedRevision` (integer, required)
- `experienceId` (string, required)
- `impactConfirmed` (boolean, required)
- `permanentConfirmed` (boolean, required)
- `previewHash` (string, required)

### `granoflow_experience_merge_preview` (~41 tokens)

Preview merging one Experience into a canonical Experience with zero writes.

Input parameters:

- `canonicalExperienceId` (string, required)
- `mergedExperienceId` (required)

### `granoflow_experience_merge_apply` (~75 tokens)

Apply an approved Experience merge and return the stable redirect readback.

Input parameters:

- `canonicalExperienceId` (string, required)
- `confirmed` (boolean, required)
- `expectedCanonicalRevision` (integer, required)
- `expectedMergedRevision` (integer, required)
- `mergedExperienceId` (required)
- `previewHash` (string, required)

### `granoflow_experience_usage_link` (~59 tokens)

Link or update a confirmed task usage for an Experience.

Input parameters:

- `confirmed` (boolean, required)
- `experienceId` (string, required)
- `kind` (string, required)
- `note` (string)
- `taskId` (required)

### `granoflow_experience_usage_unlink_impact` (~46 tokens)

Preview whether unlinking an Experience from a task would leave it without task relations.

Input parameters:

- `experienceId` (string, required)
- `taskId` (required)

### `granoflow_experience_usage_unlink` (~47 tokens)

Unlink an Experience from one task without deleting Experience provenance.

Input parameters:

- `confirmed` (boolean, required)
- `experienceId` (string, required)
- `taskId` (required)

### `granoflow_knowledge_assessment_list` (~22 tokens)

List Knowledge eligibility assessments without creating cards.

### `granoflow_knowledge_assessment_get` (~33 tokens)

Get one Knowledge assessment with typed source snapshots and freshness.

Input parameters:

- `assessmentId` (string, required)

### `granoflow_knowledge_assessment_preview` (~36 tokens)

Preview eligibility, disposition, learning cost, and duplicate handling with zero writes.

Input parameters:

- `candidates` (array, required)

### `granoflow_knowledge_assessment_apply` (~63 tokens)

Apply only approved Knowledge assessment operations; this does not materialize cards.

Input parameters:

- `approvedOperationIds` (array, required)
- `idempotencyKey` (string, required)
- `previewHash` (string, required)
- `previewToken` (string, required)

### `granoflow_knowledge_materialization_list` (~27 tokens)

List approved Knowledge materializations backed by existing Review Notes and Cards.

### `granoflow_knowledge_materialization_get` (~40 tokens)

Get one Knowledge materialization with Note, Cards, source health, and control evidence.

Input parameters:

- `materializationId` (string, required)

### `granoflow_knowledge_materialization_preview` (~37 tokens)

Preview atomic Knowledge Note/Card creation or existing-Knowledge reuse with zero writes.

Input parameters:

- `candidates` (array, required)

### `granoflow_knowledge_materialization_apply` (~63 tokens)

Apply approved Knowledge materializations atomically and return Note/Card readback.

Input parameters:

- `approvedOperationIds` (array, required)
- `idempotencyKey` (string, required)
- `previewHash` (string, required)
- `previewToken` (string, required)

### `granoflow_knowledge_control_preview` (~47 tokens)

Preview implemented or verified system-control evidence with zero writes.

Input parameters:

- `evidence` (object, required)
- `materializationId` (string, required)
- `status` (string, required)

### `granoflow_knowledge_control_apply` (~63 tokens)

Apply approved control evidence. Verified status remains App-owned and requires readback evidence.

Input parameters:

- `idempotencyKey` (string, required)
- `operationId` (string, required)
- `previewHash` (string, required)
- `previewToken` (string, required)

### `granoflow_task_knowledge_pack` (~54 tokens)

Build a zero-write task analysis pack with separate Evidence, Experience, and Knowledge lanes.

Input parameters:

- `limitPerLane` (integer)
- `query` (string, required)
- `taskId` (string, required)

### `granoflow_task_knowledge_references` (~32 tokens)

List current structured Task Work references for one task.

Input parameters:

- `taskId` (string, required)

### `granoflow_task_knowledge_adoption_preview` (~47 tokens)

Preview adopted, considered, or rejected Knowledge Pack decisions. Only adopted operations can write.

Input parameters:

- `decisions` (array, required)
- `taskId` (string, required)

### `granoflow_task_knowledge_adoption_apply` (~74 tokens)

Apply only approved adopted references and return Reference, Usage, and association readback.

Input parameters:

- `approvedOperationIds` (array, required)
- `idempotencyKey` (string, required)
- `previewHash` (string, required)
- `previewToken` (string, required)
- `taskId` (string, required)

### `granoflow_task_knowledge_audit_preview` (~46 tokens)

Preview removal of Task Work references no longer present in the fully rewritten document.

Input parameters:

- `desiredReferences` (array, required)
- `taskId` (string, required)

### `granoflow_task_knowledge_audit_apply` (~71 tokens)

Apply approved stale-reference removals while preserving applied Knowledge Usage history.

Input parameters:

- `approvedOperationIds` (array, required)
- `idempotencyKey` (string, required)
- `previewHash` (string, required)
- `previewToken` (string, required)
- `taskId` (string, required)

### `granoflow_task_knowledge_usage_preview` (~59 tokens)

Preview referenced to applied, validated, or contradicted Knowledge Usage transition with evidence.

Input parameters:

- `evidence` (object, required)
- `materializationId` (required)
- `status` (string, required)
- `taskId` (string, required)

### `granoflow_task_knowledge_usage_apply` (~70 tokens)

Apply one approved Knowledge Usage status transition and preserve its append-only event.

Input parameters:

- `idempotencyKey` (string, required)
- `operationId` (string, required)
- `previewHash` (string, required)
- `previewToken` (string, required)
- `taskId` (string, required)

### `granoflow_project_knowledge_usages` (~40 tokens)

List Knowledge actually adopted by tasks in one project. The result is read-only and derived.

Input parameters:

- `projectId` (string, required)

### `granoflow_milestone_knowledge_usages` (~42 tokens)

List Knowledge actually adopted by tasks in one milestone. The result is read-only and derived.

Input parameters:

- `milestoneId` (string, required)

### `granoflow_review_card_draft_schema` (~55 tokens)

Fetch the Granoflow review card draft template and field schema from the running app. Call before creating reviewCardDrafts so card types, note fields, layouts, and fallbacks match app import rules.

### `granoflow_review_card_similar` (~71 tokens)

Find potentially similar Granoflow review cards. The app prefers vector search and falls back to agent-supplied keywords; the agent must prefilter results before showing them to the user.

Input parameters:

- `keywords` (array)
- `limit` (integer)
- `summary` (string, required)

### `granoflow_review_card_authoring_preview` (~66 tokens)

Preview controlled review-card creation, existing-card linking, or field-level updates for an existing project or inbox task. This endpoint performs no writes and returns a confirmation token plus shared-note impact.

Input parameters:

- `operations` (array, required)
- `taskId` (string, required)

### `granoflow_review_card_authoring_apply` (~80 tokens)

Apply only user-approved operations from a current review-card authoring preview. Returns app-owned readback; never call without explicit approval of the previewed operations.

Input parameters:

- `approvedFieldsByOperation` (object)
- `approvedOperationIds` (array, required)
- `previewHash` (string, required)
- `previewToken` (string, required)

### `granoflow_context_pack` (~109 tokens)

Read a structured Granoflow work-memory context pack for the current agent task. Returns typed facts and match signals, not planning hints or recommendations.

Input parameters:

- `client` (string)
- `dryRun` (boolean): When true, previews the request without calling the app.
- `limit` (integer)
- `projectId` (string)
- `query` (string)
- `repo` (string)
- `scope` (string)
- `taskId` (string)

### `granoflow_historical_task_candidates` (~102 tokens)

Read App-owned historical task candidate facts and bounded evidence for one current task. The tool never ranks again or turns relationship facts into recommendations.

Input parameters:

- `dryRun` (boolean): When true, previews the request without calling the app.
- `errorText` (string)
- `limit` (integer)
- `module` (string)
- `paths` (array)
- `summary` (string)
- `taskId` (string, required)

### `granoflow_memory_batch_preview` (~92 tokens)

Ask the running Granoflow app to preview an AI-agent memory batch before any write. Granoflow owns project/milestone matching and duplicate signals; this MCP tool only forwards after capability checks.

Input parameters:

- `dryRun` (boolean): When true, previews the HTTP request without calling the app.
- `items` (array, required)
- `source` (object)
- `target` (object)

### `granoflow_context_steward_status` (~49 tokens)

Read Granoflow project and milestone context-steward state, including active milestones and the archived-milestone final-snapshot policy.

Input parameters:

- `projectId` (string)

### `granoflow_project_context_attachments_ensure` (~68 tokens)

Ensure Granoflow canonical project context YAML attachments exist: project_snapshot.yaml and project_rules.yaml. Defaults to dry-run.

Input parameters:

- `dryRun` (boolean): When true, previews missing attachments without writing.
- `projectId` (string, required): Granoflow project id.

### `granoflow_project_context_attachment_read` (~113 tokens)

Read a bounded section of project_snapshot.yaml or project_rules.yaml. Defaults to header, summary, and the smallest matching section; full read requires explicit intent.

Input parameters:

- `allowFullRead` (boolean)
- `attachment` (string)
- `dryRun` (boolean): When true, previews the HTTP request without calling the app.
- `intent` (string)
- `projectId` (string, required): Granoflow project id.
- `query` (string)
- `section` (string)

### `granoflow_project_context_attachment_reconcile` (~74 tokens)

Check or reconcile project context YAML freshness. Low-risk factual snapshot deltas can reconcile; rules and wording conflicts return a proposal.

Input parameters:

- `attachment` (string)
- `dryRun` (boolean): When true, previews reconcile without writing.
- `projectId` (string, required): Granoflow project id.

### `granoflow_project_context_attachment_write` (~110 tokens)

Write a project context YAML attachment through app-owned safety gates. project_rules.yaml requires confirmation; secret/privacy risks fail closed.

Input parameters:

- `attachment` (string)
- `confirmed` (boolean): Required for project_rules.yaml rule, wording, or decision-note changes.
- `content` (string, required)
- `dryRun` (boolean): When true, previews the HTTP request without calling the app.
- `projectId` (string, required): Granoflow project id.
- `section` (string)

### `granoflow_project_interaction_style` (~62 tokens)

Resolve the current project's explanation style. Missing or incomplete settings default to newcomer-friendly, detailed explanations; this tool never asks the user to choose.

Input parameters:

- `dryRun` (boolean)
- `projectId` (string, required): Granoflow project id.

### `granoflow_project_context_update` (~87 tokens)

Update only a Granoflow project description as living context. Defaults to dry-run and requires an evidence summary.

Input parameters:

- `description` (string, required)
- `dryRun` (boolean): When true, previews the request without writing.
- `evidenceSummary` (string, required): Short evidence summary for why this context description changed.
- `projectId` (string, required): Granoflow project id.

### `granoflow_milestone_context_update` (~100 tokens)

Update only an active Granoflow milestone description as living context. Fails closed for archived milestones and defaults to dry-run.

Input parameters:

- `description` (string, required)
- `dryRun` (boolean): When true, previews the request without writing.
- `evidenceSummary` (string, required): Short evidence summary for why this context description changed.
- `milestoneId` (string, required): Granoflow milestone id.
- `projectId` (string)

### `granoflow_milestone_context_archive` (~114 tokens)

Preview a milestone archive context closure: final milestone state plus parent project description update. Real writes fail closed until the app exposes a safe archive API.

Input parameters:

- `closure` (object, required)
- `confirmArchive` (boolean): Reserved for future safe archive writes; dry-run remains the normal mode.
- `dryRun` (boolean): When true, previews the closure without writing.
- `milestoneId` (string, required): Granoflow milestone id.
- `projectId` (string, required): Parent Granoflow project id.

### `granoflow_task_completion_record` (~106 tokens)

Record an engineering task completion through Granoflow's controlled work-memory API and existing task write/complete paths.

Input parameters:

- `client` (string)
- `decisions` (array)
- `dryRun` (boolean): When true, previews the request without writing.
- `outcome` (string, required)
- `repo` (string)
- `source` (object)
- `summary` (string, required)
- `tags` (array)
- `title` (string, required)

### `granoflow_review_card_record` (~101 tokens)

Record a reusable review-card lesson through Granoflow's controlled work-memory API. The app may fail closed until controlled review-card import/create paths are available.

Input parameters:

- `client` (string)
- `dryRun` (boolean): When true, previews the request without writing.
- `problem` (string, required)
- `solution` (string, required)
- `source` (object)
- `tags` (array)
- `title` (string, required)

### `granoflow_tag_list` (~38 tokens)

List tags from the Granoflow local catalog.

Input parameters:

- `kind` (string): Optional tag kind filter forwarded to the Local HTTP API.

### `granoflow_tag_create` (~62 tokens)

Create a custom Granoflow tag. Defaults to dry-run.

Input parameters:

- `dryRun` (boolean): When true, previews the request without writing.
- `iconKey` (string)
- `label` (string, required)
- `slug` (string)

### `granoflow_source_tags_ensure` (~63 tokens)

Ensure the AI and 人工 completion source tags exist in Granoflow. Idempotent: reuses existing tags matched by slug or label.

Input parameters:

- `dryRun` (boolean): When true, only inspects the current catalog without creating missing tags.

### `granoflow_task_list` (~39 tokens)

List tasks from Granoflow. Optionally filter by tag slug.

Input parameters:

- `tag` (string): Return only tasks containing this tag slug.

### `granoflow_task_export` (~128 tokens)

Export task details, reusable lessons, and App-admitted prototype inputs. The App is the sole execution-admission authority; this tool never guesses current or latest prototype versions.

Input parameters:

- `assetMode` (string): Use file to request short-lived decrypted package paths.
- `fetchMissing` (boolean): Allow the App to fetch a missing local package before export.
- `includePrototypes` (boolean): Include structured prototype admission and admitted assets.
- `taskId` (string, required): Granoflow task id.
- `ttlSeconds` (integer): Temporary prototype asset lifetime, capped at 600 seconds.

### `granoflow_task_validate` (~43 tokens)

Validate an AI-agent task result before importing it into Granoflow.

Input parameters:

- `input` (object, required): JSON object sent to the Granoflow Local HTTP API.

### `granoflow_task_import` (~68 tokens)

Import an AI-agent task result into Granoflow. Use dryRun first unless the user explicitly asks to write.

Input parameters:

- `dryRun` (boolean): When true, previews the request without writing.
- `input` (object, required): JSON object sent to the Granoflow Local HTTP API.

### `granoflow_task_history_mutate` (~172 tokens)

Write evidence-based task timestamps and historical Granoflow facts through the dedicated AI-agent API. AI execution may update startedAt while the task remains pending so it never claims the human doing focus slot; node-managed completion may correct startedAt/endedAt after status=done. Every create mutation requires shared AI/automation authoringEvidence for an action/outcome title, plain language, a real analogy, and a concrete example. Use dryRun first; when dryRun=false, the running app must advertise historical_task_mutations_v1.

Input parameters:

- `dryRun` (boolean): When true, previews without writing. Set false only with explicit user approval.
- `mutations` (array, required)
- `source` (object): Source metadata such as {kind, threadId, summary, startedAt, endedAt}.

### `granoflow_task_create` (~185 tokens)

Create a current Granoflow task from a JSON payload in pending state. Do not include createdAt, updatedAt, startedAt, endedAt, or deletedAt. AI execution keeps the task pending until its completion owner changes it to done and records its actual start through granoflow_task_history_mutate; status=doing is reserved for human focus. AI and automation callers must include input.authoringEvidence proving an action/outcome title, plain-language review, and exact real-analogy and concrete-example excerpts. Invalid evidence returns task_authoring_quality_failed before any task write. Tags not in the local catalog are skipped automatically. Optional completionSource attaches AI/人工 source tags for completed-work capture.

Input parameters:

- `dryRun` (boolean): When true, previews the request without writing.
- `input` (object, required): JSON object sent to the Granoflow Local HTTP API.

### `granoflow_task_create_structured` (~340 tokens)

Create a current Granoflow task in pending state with common structured fields. Ordinary creation never accepts startedAt or other historical physical fields. AI execution stays pending until verified completion, records its actual start through granoflow_task_history_mutate, and never claims the human doing focus slot. AI and automation callers must provide authoringEvidence for an action/outcome title, plain-language review, and exact real-analogy and concrete-example excerpts. Invalid evidence returns task_authoring_quality_failed before any task write. For a milestone-bound task, choose dueAt from context, usually today, tomorrow, or the milestone deadline. Tags not in the local catalog are skipped automatically. Defaults to dry-run.

Input parameters:

- `authoringEvidence` (object): Required for AI or automation task creation: declare an action/outcome title, plain-language review, and exact analogy/example excerpts from the description.
- `completionSource` (string): When ai or human, attach the matching AI/人工 source tag after ensuring it exists. Omit or unknown means no source tag.
- `description` (string)
- `dryRun` (boolean): When true, previews the request without writing.
- `dueAt` (string): Task deadline. When milestoneId is supplied, choose from context, usually today, tomorrow, or the milestone deadline, and never silently place it after the milestone deadline.
- `milestoneId` (string)
- `projectId` (string)
- `remindAt` (string)
- `status` (string): Ordinary current-task creation starts pending; omit or pass pending.
- `tags` (array)
- `title` (string, required)

### `granoflow_task_update` (~132 tokens)

Update a current Granoflow task through the Local HTTP API. Do not include historical physical fields. AI execution must not set status=doing: keep pending, record actual startedAt through granoflow_task_history_mutate, and complete through NodeService or granoflow_task_finish. Human manual focus may set doing. Tags not in the local catalog are skipped automatically.

Input parameters:

- `dryRun` (boolean): When true, previews the request without writing.
- `input` (object, required): JSON object sent to the Granoflow Local HTTP API.
- `taskId` (string, required): Granoflow task id.

### `granoflow_task_update_structured` (~229 tokens)

Update a current Granoflow task with common structured fields. AI execution never sets status=doing: it remains pending until verified completion and writes actual execution time through granoflow_task_history_mutate. status=doing is for human manual focus and keeps the App-recorded start behavior. When moving it into a milestone, choose dueAt from context, usually today, tomorrow, or the milestone deadline. Defaults to dry-run.

Input parameters:

- `description` (string)
- `dryRun` (boolean): When true, previews the request without writing.
- `dueAt` (string): Task deadline. When milestoneId is supplied, choose from context, usually today, tomorrow, or the milestone deadline, and never silently place it after the milestone deadline.
- `expectedUpdatedAt` (string)
- `milestoneId` (string)
- `projectId` (string)
- `remindAt` (string)
- `status` (string)
- `taskId` (string, required): Granoflow task id.
- `taskReview` (string)
- `title` (string)

### `granoflow_task_review_update` (~78 tokens)

Safely write a confirmed structured Task Review to any task, including completed inbox tasks, using the latest task revision. Review cards and context promotion remain separate controlled steps.

Input parameters:

- `dryRun` (boolean)
- `expectedUpdatedAt` (string, required)
- `taskId` (string, required)
- `taskReview` (string, required)

### `granoflow_task_completion_summary_update` (~67 tokens)

Safely update a task description that already preserves all user text and contains exactly one Task Completion Summary managed block.

Input parameters:

- `description` (string, required)
- `dryRun` (boolean)
- `expectedUpdatedAt` (string, required)
- `taskId` (string, required)

### `granoflow_task_complete` (~85 tokens)

Low-level node-less compatibility endpoint. Never call it for a task with Work Document nodes; NodeService owns completion for node-backed tasks.

Input parameters:

- `dryRun` (boolean): When true, previews the request without writing.
- `input` (object): JSON object sent to the Granoflow Local HTTP API.
- `taskId` (string, required): Granoflow task id.

### `granoflow_task_attachment_list` (~29 tokens)

List attachments for a Granoflow task.

Input parameters:

- `taskId` (string, required)

### `granoflow_logical_attachment_replace` (~115 tokens)

Replace the current typed project, milestone, or task artifact and require App-owned SHA-256 readback before it becomes current.

Input parameters:

- `dryRun` (boolean)
- `entityId` (string, required)
- `entityType` (string, required)
- `expectedUpdatedAt` (string, required)
- `filePath` (string, required)
- `idempotencyKey` (string, required)
- `logicalSlot` (string, required)
- `visualConfirmed` (boolean): Must be true when logicalSlot is ui_prototype.

### `granoflow_logical_attachment_read` (~71 tokens)

Read bounded Markdown or YAML content and App-owned SHA-256 for one current logical attachment. Acceptance HTML is previewed by the App and uses replace-response hash readback.

Input parameters:

- `attachmentId` (string, required)
- `entityId` (string, required)
- `entityType` (string, required)

### `granoflow_project_design_baseline_import` (~115 tokens)

Import one validated high-fidelity prototype package as the App-owned project design baseline. The App owns package validation, immutable versions, project linking, deduplication, and exact SHA-256 readback.

Input parameters:

- `dryRun` (boolean)
- `filePath` (string, required): Absolute path to a local .zip package.
- `idempotencyKey` (string, required)
- `projectId` (string, required)
- `prototypeId` (string): Existing App-owned prototype id when adding a new baseline version.

### `granoflow_project_design_baseline_read` (~65 tokens)

Read back one exact App-owned project design baseline reference. Never guesses the latest version.

Input parameters:

- `expectedPackageSha256` (string, required)
- `projectId` (string, required)
- `prototypeId` (string, required)
- `versionId` (string, required)

### `granoflow_project_work_evaluate` (~71 tokens)

Evaluate the current Project Work YAML for a manual or automatic action. Partial attachment is allowed; gated actions fail with all relevant missing paths.

Input parameters:

- `action` (string, required)
- `dryRun` (boolean)
- `projectId` (string, required)
- `requiredPaths` (array)

### `granoflow_project_work_confirm` (~78 tokens)

Confirm the exact current Project Work content hash in the App. Confirmation does not authorize execution, commit, push, publish, deploy, deletion, payment, or messaging.

Input parameters:

- `confirmed` (boolean, required)
- `dryRun` (boolean)
- `expectedContentSha256` (string, required)
- `projectId` (string, required)

### `granoflow_task_attachment_add_markdown` (~88 tokens)

Conditionally attach a versioned Task Work Document, legacy Task Analysis/Plan, or Task Delivery Markdown file and verify App-owned content/hash readback.

Input parameters:

- `dryRun` (boolean)
- `expectedTaskUpdatedAt` (string, required)
- `filePath` (string, required)
- `idempotencyKey` (string, required)
- `taskId` (string, required)

### `granoflow_task_attachment_read_markdown` (~58 tokens)

Read a bounded Task Work Document, legacy Task Analysis/Plan, or Task Delivery Markdown attachment with its App-owned SHA-256 for verification.

Input parameters:

- `attachmentId` (string, required)
- `taskId` (string, required)

### `granoflow_task_attachment_delete` (~51 tokens)

Delete a task attachment after explicit confirmation.

Input parameters:

- `attachmentId` (string, required)
- `confirmed` (boolean, required)
- `dryRun` (boolean)
- `taskId` (string, required)

### `granoflow_task_node_list` (~41 tokens)

Read the latest Granoflow task nodes before planning, executing, or reconciling cross-device changes.

Input parameters:

- `taskId` (string, required)

### `granoflow_task_node_batch_create` (~76 tokens)

Atomically create an ordered, idempotent task node batch through the Granoflow NodeService.

Input parameters:

- `dryRun` (boolean)
- `expectedTaskUpdatedAt` (string, required)
- `idempotencyKey` (string, required)
- `nodes` (array, required)
- `taskId` (string, required)

### `granoflow_task_node_update` (~74 tokens)

Update a task node title or apply pending/finished status with optimistic concurrency.

Input parameters:

- `dryRun` (boolean)
- `expectedUpdatedAt` (string, required)
- `nodeId` (string, required)
- `status` (string)
- `taskId` (string, required)
- `title` (string)

### `granoflow_task_node_delete` (~68 tokens)

Soft-delete a task node tree after a confirmed Work Document amendment and explicit confirmation.

Input parameters:

- `confirmed` (boolean, required)
- `dryRun` (boolean)
- `expectedUpdatedAt` (string, required)
- `nodeId` (string, required)
- `taskId` (string, required)

### `granoflow_task_finish` (~355 tokens)

Finish a node-less compatibility task after its required Delivery gate and verify status=done. For AI execution, keep the task pending until this completion action and supply the captured actual startedAt plus confirmed endedAt; never claim status=doing or substitute discussion/creation time. Human manual focus may already have an App-recorded start from doing. Do not use for node-backed tasks. taskReview/reviewCardDrafts remain legacy explicit-inline compatibility only; deferred Review is the default.

Input parameters:

- `completionSource` (string): Defaults to ai when an agent finishes the task. Use human for clearly human-completed work, or unknown to skip source tags.
- `confirmComplete` (boolean): Must be true when dryRun=false.
- `dryRun` (boolean): When true, previews the update/complete/import/readback sequence.
- `endedAt` (string): Task end time inferred from the current agent conversation, preferably ISO-like.
- `milestoneId` (string): Required when taskReview or reviewCardDrafts are provided.
- `projectId` (string): Required when taskReview or reviewCardDrafts are provided.
- `reviewCardDrafts` (array): One card per durable knowledge point worth long-term memory; omit when there is nothing worth remembering.
- `startedAt` (string): Actual execution start time. AI execution captures this while the task stays pending and supplies it at completion. Do not use task discussion or creation time.
- `summary` (string): Short import summary for the completion, review, and card write.
- `taskId` (string, required): Granoflow task id.
- `taskReview` (string): Meaningful task review only. Omit this when the content would be a mere activity log.

### `granoflow_task_resolve` (~65 tokens)

Resolve Granoflow task candidates by title without creating or updating data.

Input parameters:

- `includeDone` (boolean)
- `matchMode` (string)
- `milestoneId` (string)
- `projectId` (string)
- `query` (string, required)

### `granoflow_project_list` (~17 tokens)

List Granoflow projects.

### `granoflow_project_resolve` (~49 tokens)

Resolve Granoflow project candidates by title without creating or updating data.

Input parameters:

- `includeDone` (boolean)
- `matchMode` (string)
- `query` (string, required)

### `granoflow_project_create` (~72 tokens)

Create a Granoflow project with common structured fields. Defaults to dry-run.

Input parameters:

- `description` (string)
- `domainTag` (string)
- `dryRun` (boolean): When true, previews the request without writing.
- `status` (string)
- `title` (string, required)

### `granoflow_project_update` (~85 tokens)

Update a Granoflow project with common structured fields. Defaults to dry-run.

Input parameters:

- `description` (string)
- `domainTag` (string)
- `dryRun` (boolean): When true, previews the request without writing.
- `projectId` (string, required): Granoflow project id.
- `status` (string)
- `title` (string)

### `granoflow_project_delete` (~69 tokens)

Safely delete a Granoflow project. Defaults to dry-run and requires confirmTitle for writes.

Input parameters:

- `allowLinkedTasks` (boolean)
- `confirmTitle` (string)
- `dryRun` (boolean)
- `projectId` (string, required): Granoflow project id.

### `granoflow_milestone_list` (~19 tokens)

List Granoflow milestones.

### `granoflow_milestone_resolve` (~59 tokens)

Resolve Granoflow milestone candidates by title without creating or updating data.

Input parameters:

- `includeDone` (boolean)
- `matchMode` (string)
- `projectId` (string)
- `query` (string, required)

### `granoflow_milestone_create` (~135 tokens)

Create a Granoflow milestone with common structured fields. When dueAt is omitted, defaults to the next available Saturday for the project. Defaults to dry-run.

Input parameters:

- `description` (string)
- `dryRun` (boolean): When true, previews the request without writing.
- `dueAt` (string): Explicit deadline. When omitted, uses the next local Saturday at 23:59:59.000 and advances by whole weeks past existing deadlines in the same project.
- `projectId` (string, required): Granoflow project id.
- `status` (string)
- `title` (string, required)

### `granoflow_milestone_delete` (~71 tokens)

Safely delete a Granoflow milestone. Defaults to dry-run and requires confirmTitle for writes.

Input parameters:

- `allowLinkedTasks` (boolean)
- `confirmTitle` (string)
- `dryRun` (boolean)
- `milestoneId` (string, required): Granoflow milestone id.

### `granoflow_milestone_update` (~116 tokens)

Update a Granoflow milestone with common structured fields. Defaults to dry-run. Use granoflow_milestone_context_update for description upkeep; description updates fail closed for archived milestones.

Input parameters:

- `description` (string)
- `dryRun` (boolean): When true, previews the request without writing.
- `dueAt` (string)
- `milestoneId` (string, required): Granoflow milestone id.
- `projectId` (string)
- `status` (string)
- `title` (string)

### `granoflow_review_day_show` (~35 tokens)

Show a Granoflow daily review by date.

Input parameters:

- `date` (string, required): Date in YYYY-MM-DD format.

### `granoflow_api_request` (~74 tokens)

Run an allowed Granoflow Local HTTP API request. Prefer dedicated tools when available.

Input parameters:

- `dryRun` (boolean): When true, previews write requests.
- `input` (object): JSON object sent to the Granoflow Local HTTP API.
- `method` (string)
- `path` (string, required)

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/com-granoflow-mcp-server/granoflow-mcp-server#diagnostics

## Score history

- 2026-08-03: 56
- 2026-08-02: 49
- 2026-08-01: 20
- 2026-07-31: 25
- 2026-07-29: 43
- 2026-07-28: 24
- 2026-07-27: 43

## Links

- npm package: https://www.npmjs.com/package/@granoflow/mcp-server
- Socket report: https://socket.dev/npm/package/@granoflow/mcp-server
- Repository: https://github.com/granoflow/granoflow-mcp-server
- Changelog RSS feed: https://verifymcp.io/servers/com-granoflow-mcp-server/granoflow-mcp-server/changelog.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-granoflow-mcp-server/granoflow-mcp-server/changelog.json
- HTML version of this page: https://verifymcp.io/servers/com-granoflow-mcp-server/granoflow-mcp-server
