Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

ddflow

PYPI · DDFLOW-MCP · 3 COMPONENTS · SCANNED OCT 5

Work-queue kernel for AI coding agents: dependencies, worktree isolation, quality gates, recovery

49 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security100
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
  • 0 of 2 dependencies flagged as unhealthy. View diagnostics → Pass
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to delian/ddflow-mcp). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 0 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability0
  • Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Stability & Change Management0
  • Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Tool Coverage0
  • Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.Unverified
Tool Safety0
  • Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.Unverified
Capabilities0
  • Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet.Unverified

Unverified: 5 categories

Categories scored 0 because our sandbox has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you. How we score packages →

Install

How do I install the ddflow MCP server?

ddflow runs locally as a PyPI package, launched with uvx ddflow-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

pypi · ddflow-mcp

# add to Claude Code
claude mcp add delian-ddflow-mcp -- uvx ddflow-mcp
// .cursor/mcp.json
{
  "mcpServers": {
    "delian-ddflow-mcp": {
      "command": "uvx",
      "args": [
        "ddflow-mcp"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "delian-ddflow-mcp": {
      "command": "uvx",
      "args": [
        "ddflow-mcp"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add delian-ddflow-mcp -- uvx ddflow-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "delian-ddflow-mcp": {
      "type": "local",
      "command": [
        "uvx",
        "ddflow-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add delian-ddflow-mcp --command uvx --arg ddflow-mcp
# ~/.hermes/config.yaml
mcp_servers:
  delian-ddflow-mcp:
    command: "uvx"
    args: ["ddflow-mcp"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "delian-ddflow-mcp": {
      "Transport": "stdio",
      "Command": "uvx",
      "Arguments": [
        "ddflow-mcp"
      ]
    }
  }
}
# add to Vellum
assistant mcp add delian-ddflow-mcp -t stdio -c uvx -a ddflow-mcp
// mcp.json
{
  "mcpServers": {
    "delian-ddflow-mcp": {
      "command": "uvx",
      "args": [
        "ddflow-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 5 Oct 26 +5
    • Source repository: unverified → pass ▲ security
    • Package version: 0.1.11 → 0.1.13 functional
  • 4 Oct 26 −20
    • Provenance: pass → unverified ▼ security
    • Stability: 0.03 → unverified ▼ security
    • Tool safety: pass → unverified ▼ security
    • Malware scan: unverified → pass ▲ security
    • Schema quality: 100 → unverified ▼ functional
    • Tool coverage: 100 → unverified ▼ functional
    • Capabilities: fail → unverified ▼ functional
    • Schema quality: 190 → 157 ▲ functional
    • Package version: 0.1.11 → 0.1.13 functional
    • Package version: 0.1.11 → 0.1.12 functional
  • 3 Oct 26 0
    • Malware scan: unverified → pass ▲ security
    • Stability: unverified → 0.03 ▲ functional
    • Package version: 0.1.10 → 0.1.11 functional
  • 2 Oct 26 64

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 7 Oct 2026 · Analysed pypi/ddflow-mcp@0.1.18

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem pypi
Reason Verified
Discovered via Registry attestation endpoint
Source repo delian/ddflow-mcp
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/delian/ddflow-mcp/.github/workflows/publish.yml@refs/heads/main
Rekor log index 3107963531
Predicate type PyPI publish attestation https://docs.pypi.org/attestations/publish/v1
Subject digest sha256:e6676e0f43f9bd0bcc9867af867c669502f1fa1f7cdbf5fcc8ad53b6ceadf680

Background: How many MCP packages publish verified provenance →

Install scripts 1 script
Hook Tier Command
build_backend allowlisted hatchling.build

Background: Why install scripts are a supply-chain risk →

Dependencies 2 packages
Packages resolved 2
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 106 exposed · ~16,898 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
ddflow_abandon ~158

Stop work on an item without completing it, with a reason. Use when a task turns out to be unnecessary or impossible. DIFFERENT from blocking: a blocked item is waiting and will resume; an abandoned one will not, and so it stops holding its phase open — which an unfinished task otherwise does forever, since nothing can ever finish it.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
forceboolean–Abandon although a sub-task is still open. Those sub-tasks are NOT abandoned with it: decide about each, or they sit under a parent nobody will finish.
idstringyesItem id.
reasonstringyesWhy it is being dropped.

No output schema declared.

No examples provided.

ddflow_bisect ~121

Which earlier test file makes `victim` fail only in full-suite order? Delta-debugs the files before it, running `cmd` many times. Exit 2: nothing to report.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
candidatesstring–Comma-separated files in run order.
cmdstringyesTest command; {tests} = the list.
timeoutinteger–Seconds per run (600).
victimstringyesFailing test id.

No output schema declared.

No examples provided.

ddflow_block ~110

Mark an item blocked on something outside the queue — a decision, an upstream outage, an operator question. Better than leaving it claimed: a blocked item states its reason. A DONE or ABANDONED item needs reopen.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
idstringyesItem id.
reasonstringyesWhat it is waiting on.
reopenboolean–Allow blocking a DONE or ABANDONED item.

No output schema declared.

No examples provided.

ddflow_board ~53

The whole work queue as a readable board, with the critical path.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
phasestring–Restrict to one phase.

No output schema declared.

No examples provided.

ddflow_brief ~181

START HERE every session. Returns a budgeted pack: work recoverable after a crash, the current item, what is ready to start now, why everything else is blocked, and the past lessons ranked as relevant to this task. Use this INSTEAD of reading the project's lesson or rule files — it is the same information retrieved for the task at hand, at a fraction of the tokens.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
check_recoveryboolean–Also scan for crashed agents' worktrees and lead with them: unclaimed work left by a dead process is the one thing to know BEFORE picking up something new.
itemstring–Focus on this phase or task id (optional).
phasestring–Restrict the ready set to this phase (optional).

No output schema declared.

No examples provided.

ddflow_bug_file_tasks ~76

File a fix task for every open bug that has none (one-shot after an upgrade; `ddflow_bug_found` files one per bug by default).

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
dry_runboolean–List what would be filed; write nothing.

No output schema declared.

No examples provided.

ddflow_bug_fixed ~216

Close a bug. Requires the name of the regression test that would catch it again — write the test, watch it FAIL against the unfixed code, then close.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
changelogstring–Optional 'Fixed: text' (any category), or skip.
idstringyesBug id.
lessonstring–Id of an EXISTING lesson this bug belongs to.
lesson_rulestring–The lesson in full — the transferable rule, not the incident. A future agent on a different task has to be able to apply it.
lesson_titlestring–Capture a lesson at the same time.
regression_teststring–Test that now guards this. Several: separate them with ',' or ';', or pass regression_tests.
regression_testsarray–The tests that now guard this, one per element -- the list form of regression_test. One of the two is required.

No output schema declared.

No examples provided.

ddflow_bug_found ~271

Report a bug the moment you find it, BEFORE fixing it. Recording it first makes the fix accountable: `ddflow_bug_fixed` refuses to close one without a regression test. A hunt that records nothing looks like one that found nothing.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
check_onlyboolean–Dry run: write nothing, return the `candidates` this add would be refused for.
globsstring–The fix task's files; default: the item's globs.
idstring–Stable id, e.g. 'B1'. You will cite it when closing.
itemstring–The task it was found in or affects.
no_taskboolean–File no fix task (fixed in the same commit).
relationstring–Answer to a 'possible duplicate' refusal: new | extends:ID | duplicate_of:ID | related:ID (the refusal lists candidates and options). Omit at first.
scopestring–project (default) or ddflow.
severitystring–low|medium|high|critical.
summarystringyesWhat is wrong, in one line.
titlestring–Short headline.

No output schema declared.

No examples provided.

ddflow_bug_invalid ~174

Close a bug as a FALSE finding -- nothing was broken, so nothing was fixed. Never counts as a fix. Requires the reason; give the probe or test that showed it false as evidence. Refused (exit 3) for an unknown id or a bug already closed; a real bug is closed with `ddflow_bug_fixed` instead. `reopen`: instead UNDO a closure (fixed or invalid) made by mistake.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
evidencestring–The probe command or test node id that showed it false.
idstringyesBug id.
reasonstringyesWhy the finding is false (with reopen: why reopen).
reopenboolean–Reopen the closed bug instead.

No output schema declared.

No examples provided.

ddflow_cadence ~96

Which periodic whole-repo passes are due — integration tests, architecture review, mutation testing, dedupe sweep, lessons compression. Derived from completed work, so there is no state file to drift.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
notestring–What the pass did, recorded with it.
ranstring–Record that this cadence just ran.

No output schema declared.

No examples provided.

ddflow_ci ~105

CI parity: run the pre-push checks on the branch merged with the base (run) or show what would run (status).

NameTypeReqDescription
actionstring–run | status (default).
as_agentstring–A subagent's own name, this call only.
basestring–Branch merged in first (run).
commandstring–Override [ci].command (run).
refstring–Commit to check (run).

No output schema declared.

No examples provided.

ddflow_claim ~261

Lease an item and create its isolated git worktree. Refuses (exit 3) if another agent holds it or holds an item whose file globs overlap, and names what you could take instead. NEVER steals an expired lease: a crashed agent's worktree often holds finished work.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
forceboolean–Override a refusal. Legitimate only to retry after `ddflow_recover` said a crashed agent's worktree holds nothing. Forcing past a dependency or live lease is how two agents write one file; recorded e…
globsstring–Comma-separated path globs this work will write.
idstringyesItem id to claim.
no_worktreeboolean–Lease the item without creating a worktree. For work that is not a code change — a research or review task.
notestring–What you intend to do.
resourcesstring–Physical resources this claim holds, e.g. 'gpu:2'; they REPLACE the item's declared ones. Refused (exit 3) when live claims already use the capacity ([schedule] resources), every holder counted.

No output schema declared.

No examples provided.

ddflow_cleanup ~115

Classify every ddflow worktree and branch: merged (safe to remove), unmerged (carries commits nobody landed), dirty (uncommitted edits: a human looks), orphan, or stale branch. Reports by default; apply=true removes merged worktrees and branches and lands commits for items the queue considers done. A dirty tree is NEVER touched automatically: it exists nowhere else.

NameTypeReqDescription
applyboolean–Perform the safe actions.
as_agentstring–A subagent's own name, this call only.

No output schema declared.

No examples provided.

ddflow_companions ~95

Which companion MCP servers serve this project's gates, which are installed, which an agent launches. Without them, agent gates pass on assertion. Exit 2: a default one is missing or unregistered. Read-only; never installs or launches.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
no_probeboolean–Skip the detection probes (faster, less certain).

No output schema declared.

No examples provided.

ddflow_companions_add ~128

WRITES the agent config: registers companion MCP servers that are ALREADY installed (exit 3 for one that is not). dry_run=true FIRST; show the operator the entry: which servers an agent launches is their decision.

NameTypeReqDescription
agentsstring–Comma-separated agent keys (default: claude).
as_agentstring–A subagent's own name, this call only.
dry_runboolean–Report the exact entry that would be written; write nothing.
idstring–Comma-separated ids; default: every installed one.

No output schema declared.

No examples provided.

ddflow_companions_verify ~88

Launch MCP companions and require a JSON-RPC answer to `initialize`. SPAWNS processes (opt-in). Default: registered or installed ones. Exit 1: not an MCP server; 2: unsure.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
idstring–Comma-separated ids, installed or not.

No output schema declared.

No examples provided.

ddflow_complete ~194

Finish an item. Refuses (exit 3) when a required gate has not passed, when a phase still has open tasks, or when no reviewer came from a different model family than the author. Pass your own model as 'model'.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
changelogstring–Optional 'Added|Changed|Deprecated|Removed|Fixed|Security: text', or skip.
forceboolean–Complete over unmet conditions; each is recorded as overridden, forever. Prefer `ddflow_gate_skip` with a reason: it drops one named step.
idstringyesItem id.
modelstring–The AUTHOR's model.
regression_teststring–For a fix task: the test that now guards its bug(s); closes them.
shastring–Commit sha this shipped as.

No output schema declared.

No examples provided.

ddflow_configure ~315

Read or write .ddflow/config.toml (WRITES). No arguments: every knob with value, source and meaning. `set` edits one dotted key in place (preferred); `toml` APPENDS a fragment, e.g. [gate.unit_tests] command = "pytest -q -n auto" (needs pytest-xdist). The committed file is generic project policy; anything of THIS machine or operator (a reviewer endpoint, a host, a key variable, worker counts) goes with local=true to the git-ignored .ddflow/local/config.toml, read last and never committed. A reviewer there is a `[[reviewer]]` block; `ddflow_reviewers_detect` write=true writes one.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
filterstring–Only show knobs whose name contains this.
localboolean–Write `set`/`toml` to the git-ignored .ddflow/local/config.toml instead of the committed config: for this machine's endpoints, hosts, key variables and sizing.
setstring–Dotted key to set, e.g. 'gate.unit_tests.command'. Preferred: it edits in place and works whether or not the section exists.
tomlstring–A whole TOML block to append. Fails if it would duplicate an existing table — use `set` instead then.
valuestring–The value for `set`.

No output schema declared.

No examples provided.

ddflow_decision_add ~405

Record an architectural decision so the project stays consistent and the reasoning survives: HOW the software is built (a representation, boundary, library, invariant), settled by you or the operator. ALWAYS set `globs` to the code it governs, so it reaches whoever works those files; record `alternatives` too, or they get re-proposed.

NameTypeReqDescription
alternativesstring–What was rejected, and why.
as_agentstring–A subagent's own name, this call only.
bystring–'operator' or 'agent' or a name.
check_onlyboolean–Dry run: write nothing, return the `candidates` this add would be refused for.
consequencesstring–What it costs, including what it makes harder.
contextstring–The forces: why a decision was needed at all.
decisionstringyesWhat was DECIDED (not what was discussed).
globsstring–Comma-separated paths this governs.
idstring–Stable id, e.g. 'D1'. Choose one: a generated id cannot be cited in advance.
itemstring–The task it arose from.
relationstring–Answer to a 'possible duplicate' refusal: new | extends:ID | duplicate_of:ID | related:ID (the refusal lists candidates and options). Omit at first.
sourcesstring–Where this came from, comma-separated: an ADR path, a URL, a commit sha (so an audit can check it exists).
statusstring–proposed | accepted (default) | superseded. 'proposed' is honest about a decision the operator has not ratified.
supersedesstring–Comma-separated ids this replaces.
tagsstring–Comma-separated tags.
titlestringyesThe decision as a one-line statement.

No output schema declared.

No examples provided.

ddflow_decision_applicable ~82

The architectural decisions that govern a specific item's declared files. CALL THIS BEFORE IMPLEMENTING: it is how a decision reaches the person writing the code, without them having to know it exists. Returns project-wide decisions too.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
idstringyesItem id.

No output schema declared.

No examples provided.

ddflow_decision_list ~97

Every architectural decision in force. Superseded ones are hidden unless you ask for them — they are kept, never deleted, because how the architecture got here is what a rebuild needs.

NameTypeReqDescription
allboolean–Include superseded decisions.
as_agentstring–A subagent's own name, this call only.
limitinteger–Newest decisions returned (default 25; 0 = all).

No output schema declared.

No examples provided.

ddflow_decision_show ~91

Read ONE architectural decision in full — its context, what was decided, the consequences, and what was rejected. `ddflow_decision_list` gives you the titles; this is what you read before working against one, and especially before proposing something it already considered.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
idstringyesDecision id.

No output schema declared.

No examples provided.

ddflow_decision_supersede ~92

Mark a decision replaced by a newer one. Decisions are never edited or deleted; a reversal is a new decision that names the old one.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
bystringyesThe decision that replaces it.
idstringyesThe decision being replaced.
reasonstring–Why it changed.

No output schema declared.

No examples provided.

ddflow_doctor ~50

Integrity and health check: log corruption, dependency cycles, unknown dependencies, orphaned worktrees, stale index.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.

No output schema declared.

No examples provided.

ddflow_export ~271

Documents from the log (roadmap, bugs, status, worklog, sessions, decisions, rules, changelog). No doc: list. doc: capped markdown (`truncated`). Writes only with write=true AND a repo path. action: list|enable|disable|validate (enable names you and how to stop it).

NameTypeReqDescription
actionstring–list|enable|disable|validate.
allboolean–The selected documents.
as_agentstring–A subagent's own name, this call only.
checkboolean–Is it fresh.
diffboolean–Preview a write.
docstring–Kind; omit to list.
itemstring–Bugs item.
limitinteger–At most N.
max_bytesinteger–Max 60000.
modestring–enable: whole|region|append.
pathstring–Repo path.
phasestring–One phase.
sessionstring–One session.
sincestring–From YYYY-MM-DD.
statusstring–e.g. open.
tagstring–One tag.
versionstring–One release.
writeboolean–Write to path.

No output schema declared.

No examples provided.

ddflow_external_sync ~109

Observe the items in SIBLING repositories that this queue depends on (`needs = ['run_nemo_run:132.D']`, repositories named in [schedule] repos), and record what changed in this log. An external dependency is met only once it has been observed done here, so run this before `ddflow_next` when work waits on another project. Reads the other repository; never writes it.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.

No output schema declared.

No examples provided.

ddflow_flow_choose ~150

Record a workflow choice for this project, attributed to you, with a reason the next agent will read. Make it when the operator told you, or when they left it to you -- a choice left unmade is defaulted at first use and followed from then on. The operator's config file wins over a recorded choice; the result says `in_effect: false` when it does.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
knobstringyesThe choice, e.g. port_strategy (see ddflow_flow_show).
reasonstring–Why this suits the project.
valuestringyesOne of its options.

No output schema declared.

No examples provided.

ddflow_flow_show ~109

How THIS project works: its branching model, release lines, and every workflow choice (model, integration, pr_merge, port_strategy, ...) with its value, the options, and who decided -- the operator's config, a recorded choice, or a default nobody chose. `pending` lists relevant choices nobody has made: ask the operator, or pick what suits the project with `ddflow_flow_choose`.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.

No output schema declared.

No examples provided.

ddflow_gate_record ~292

Record the outcome of a gate you performed (research, a review, a bug hunt). outcome is one of passed/failed/unavailable/partial/skipped. If a reviewer or tool could not run, record 'unavailable' with a reason, never 'passed'. Pass the reviewer's model for the family check.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
commandstring–The command you ran. With `exit_code` it makes an outcome evidence; a gate in `gates.evidence_required` is rejected without them.
evidencestring–What you ran and what it said. Required by some gates.
exit_codestring–That command's exit code.
gatestringyesGate id.
idstringyesItem id.
modelstring–REVIEWER's model, e.g. 'gemini-2.5-pro'.
outcomestringyespassed | failed | unavailable | partial | skipped
output_filestring–Path to its full output; a digest is recorded.
reasonstring–Required for failed/unavailable/partial/skipped.
reviewed_shastring–Commit reviewed (roborev review <sha>); must be the branch.
reviewer_modelstring–Like `model`; says it IS the reviewer.

No output schema declared.

No examples provided.

ddflow_gate_run ~87

Execute a command gate (tests, linters) and record the result with its evidence. Agent gates cannot be run this way; they are recorded with ddflow_gate_record.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
gatestringyesGate id, e.g. unit_tests.
idstringyesItem id.

No output schema declared.

No examples provided.

ddflow_gate_skip ~155

Skip a gate ON THE RECORD, with a mandatory reason: the auditable escape hatch. `gates.require_outcome` means a silent gate BLOCKS completion, so the alternative to a skip is forcing past everything at once; a skip names the single step dropped and why, permanently in the log. A gate in `gates.required` still blocks when skipped.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
gatestringyesGate id.
idstringyesItem id.
reasonstringyesWhy this step does not apply HERE. 'n/a' is not a reason: the next person reads this to decide whether you were right.

No output schema declared.

No examples provided.

ddflow_gate_status ~75

Where an item stands in its quality pipeline, which gate is next, and the instruction for that gate. Gates marked '?' did not run — that is a coverage gap, never a pass.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
idstringyesItem id.

No output schema declared.

No examples provided.

ddflow_gate_verify ~157

Break what a gate guards and require it to NOTICE: applies each mutation registered on the gate, runs it, requires a non-zero exit, restores the file. A gate that cannot fail reports success on every change. Exit 1: the gate did NOT catch its mutation, or none is registered. Exit 3 on a HUMAN-approval gate (nothing to mutate). A mutation whose `old` text is absent or ambiguous is a FAILURE, not a skip: the gate ran on pristine source.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
gatestringyesGate id. Must be a command gate.
idstringyesItem whose worktree to mutate in.

No output schema declared.

No examples provided.

ddflow_heartbeat ~62

Renew the lease on an item. Call periodically during long work, or the lease expires and another agent may take the item.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
idstringyesItem id.

No output schema declared.

No examples provided.

ddflow_help ~162

What ddflow IS, what it can do, and what the workflow is. Call this first if you have not used it before: the other descriptions explain one tool each and the connection instructions describe THIS repository; neither answers 'how am I meant to work here'. No argument: the loop from picking work to landing it, the exit codes, and every capability grouped by purpose. `topic`: workflow, import, gates, parallel, memory, recovery, config. Read-only; the pages are templates a project may override.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
topicstring–workflow | import | gates | parallel | memory | recovery | config. Omit for the overview, which lists them.

No output schema declared.

No examples provided.

ddflow_history ~213

ONE timeline of everything that happened: claims, releases, gates, bugs, decisions, lessons, completions. Other views say what is true now; this says how it got that way. Filter with `item` (one task's life), `kind` (a family: 'gate', 'lease.acquired', 'decision,bug'), `since`, `by_agent`. Exit 2 means nothing matched: an answer, not a failure.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
by_agentstring–Only this agent's events.
itemstring–Restrict to one item's timeline.
kindstring–Comma-separated event kinds or families: 'gate', 'lease.acquired', 'decision,bug'.
limitinteger–Most recent N entries (default 40).
sincestring–ISO timestamp lower bound.
tailinteger–Last N entries, oldest first (overrides limit).

No output schema declared.

No examples provided.

ddflow_hooks ~153

Inspect or install the enforcement git hook — the one layer of this workflow that does not depend on the agent agreeing. It refuses a commit touching paths no live lease of yours covers. `status` reports whether it is installed AND whether the policy actually blocks, since a block policy with no hook installed enforces nothing.

NameTypeReqDescription
actionstring–status (default), install, uninstall.
as_agentstring–A subagent's own name, this call only.
claudeboolean–Install/uninstall the Claude Code SessionStart hook in .claude/settings.json instead of the git hook: every session, even after compaction, starts with the ddflow brief. Other hooks there are untouch…

No output schema declared.

No examples provided.

ddflow_identify ~173

Declare WHO you are on this connection before anything that writes. Call it first when 2+ agents or subagents work this repository at once: identity attributes every claim, gate outcome and review, and the tree-derived default merges several agents in one tree into one identity with no error (a review would pass independence against itself). Pick a short stable name (your role), distinct from the others'. Idempotent. A SUBAGENT sharing its parent's connection must NOT call this; it passes `as_agent` on each call instead (the CLI's `--agent`).

NameTypeReqDescription
agentstring–A short stable name, e.g. 'reviewer-2' (letters, digits, . _ -; max 64; it names your log file). OMIT to reset to the tree-derived default.

No output schema declared.

No examples provided.

ddflow_import ~197

For a project that ALREADY HAS HISTORY and is adopting ddflow now: reads its todo checklists, lessons corpus, ADR files and unmerged branches and proposes them as queue items. Reports by default; writes NOTHING until `apply` is true. Call it right after `ddflow_setup` on any repository that is not brand new. The proposal is a GUESS: the `import-existing-project` prompt walks through fixing it. Exit 2: nothing found.

NameTypeReqDescription
applyboolean–Write the proposal. Default false: look first.
as_agentstring–A subagent's own name, this call only.
include_doneboolean–Also import already-ticked items as completed. Off by default — a finished history is not a queue, and one real project yielded 3,638 of them.
max_tasksinteger–Refuse to propose more tasks than this (default 200).

No output schema declared.

No examples provided.

ddflow_import_verify ~140

Was this project's history imported, is that still true, and did anyone FINISH it? Read-only. STATUS: what carries import provenance. STILL TRUE: whether the sources moved on (what a re-run would add) or an imported item names a missing file. FINISHED: imported tasks with no globs (the conflict detector cannot protect them) and phases claiming shipped work while a task under them is open. Call after any import. Exit 1 = findings; exit 2 = nothing ever imported. `ddflow_doctor` covers the rest.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.

No output schema declared.

No examples provided.

ddflow_job_add ~118

Register a long-running process you started some other way (torchrun, a launcher script), by pid, while it runs -- so its liveness can be checked by anyone later, including after a pid is reused.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
commandstring–What it is running, for humans.
itemstringyesItem the job is for.
logstring–Where its output goes.
pidintegeryesIts process id.

No output schema declared.

No examples provided.

ddflow_job_end ~136

Record that a job ended and how. Refused while the process is still running. The exit code defaults to the one its log recorded.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
exit_codeinteger–Override the recorded exit code.
forceboolean–End a job that runs on ANOTHER host, after checking it there. Without it such a job is refused: 'could not look' is not 'not running'.
jobstringyesJob id.
notestring–What came of it: metrics, where the output is.

No output schema declared.

No examples provided.

ddflow_job_list ~120

Long-running jobs and their LIVE status: running, exited (with the exit code its log recorded), gone (killed: no exit recorded), elsewhere (another host), or ended. Use it to decide whether to keep waiting, collect results, or restart. A long run is a WAIT, never a reason to stop working the queue.

NameTypeReqDescription
allboolean–Include jobs already recorded as ended.
as_agentstring–A subagent's own name, this call only.
itemstring–Only this item's jobs.

No output schema declared.

No examples provided.

ddflow_job_run ~202

Launch a LONG-RUNNING command for an item (a training run, a data generation, a model server) detached into its own session, so it outlives you, this server and a restarted remote-control service, and record it. Runs in the item's worktree; returns the job id, pid and log path. Then WAIT with ddflow_job_list rather than polling; `ddflow_brief` shows running jobs to the next session. Declare the item's `resources` (ddflow_update) so nobody else starts a run on the same GPUs.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
commandstringyesThe shell command.
cwdstring–Working directory (default: the item's worktree).
itemstringyesItem the job is for.
logstring–Output file (default .ddflow/local/jobs/<item>-<t>.log).

No output schema declared.

No examples provided.

ddflow_lesson_add ~431

Record a lesson so it is never re-learned. Use after any bug, any operator correction, any surprise. Make the rule transferable — a future agent on a different task must be able to apply it.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
check_onlyboolean–Dry run: write nothing, return the `candidates` this add would be refused for.
globsstring–Comma-separated globs to scan for `pattern`. Default: every tracked file.
howstring–How to apply or detect it.
idstring–Stable id you choose. Referenced by `supersedes`, by commit messages and by the reconstruction; a generated id cannot be cited in advance.
patternstring–A regex naming the mistake in CODE. Scans now and stores WHICH sites match, so `ddflow_lesson_verify` can name those that reappear. Prefer it to a remembered rule when mechanical: a count says 'worse…
relationstring–Answer to a 'possible duplicate' refusal: new | extends:ID | duplicate_of:ID | related:ID (the refusal lists candidates and options). Omit at first.
rulestring–The rule in full.
seen_instring–Comma-separated item ids where this was hit. What makes a lesson checkable later instead of merely memorable.
summarystring–The lesson in ONE paragraph, for a reader who will not open the full rule. Rendered into docs/ddflow/LESSONS-SUMMARY.md.
supersedesstring–Comma-separated lesson ids this replaces. The old one is retired, not deleted: the corpus stops growing without losing what was once believed.
tagsstring–Comma-separated tags.
titlestringyesThe rule as a one-line statement.
whystring–Why it is true / what went wrong.

No output schema declared.

No examples provided.

ddflow_lesson_search ~78

Search past lessons by relevance (BM25). Use before starting work, and whenever something surprises you.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
limitinteger–Max results (default 5).
querystringyesWhat you are about to do, in words.

No output schema declared.

No examples provided.

ddflow_lesson_verify ~100

Re-scan every lesson that declared a code `pattern` and report the sites where it has REAPPEARED. Exit 1 names them; exit 2 means no lesson declares a pattern, which is NOT a pass — it means this project has no mechanical ratchet on its lessons yet. Run after a change that touches code a lesson governs.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.

No output schema declared.

No examples provided.

ddflow_list ~264

Read-only lists, newest first, 25 rows unless `limit` (0 = the most: 1000, search 200); a cut says so. `kind`: task|phase|bug|research|session|search. Bugs: open unless `all`/`state`. History: ddflow_history.

NameTypeReqDescription
allboolean–kind=bug: include fixed/invalid.
as_agentstring–A subagent's own name, this call only.
idstring–kind=session: one session in full.
kindstringyestask|phase|bug|research|session|search
limitinteger–Rows (default 25; 0 = the most: 1000, search 200).
modestring–search: ranked|exact|regex.
ownerstring–Only this agent's rows.
phasestring–Only under this phase id.
querystring–kind=search: text to find.
sincestring–Changed at/after this ISO date.
sourcesstring–search: comma-separated record kinds.
statestring–Only this state.
tagstring–Only this tag.

No output schema declared.

No examples provided.

ddflow_loops ~118

Detect circular references and runtime loops: dependency cycles, an item claimed and given up over and over, a gate whose verdict keeps flipping, a gate failing again with identical output (repeated_failure), work completed and reopened repeatedly, duplicate items writing the same files, and a queue where events keep arriving but nothing advances. CALL THIS WHEN WORK FEELS REPETITIVE: stop and re-plan rather than retry the same thing. [] when nothing is wrong.

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.

No output schema declared.

No examples provided.

ddflow_memory_add ~272

Remember ONE operational fact about this machine, repository or working state ('this box has 8 H200s', 'use -n 16, never -n auto'). Shown at the top of every ddflow_brief and found by ddflow_recall, in every worktree at once. Not for rules (ddflow_lesson_add), events (ddflow_session_note) or how the software is built (ddflow_decision_add). Never a secret: the log is committed. Refused over [memory] max_chars (default 280).

NameTypeReqDescription
as_agentstring–A subagent's own name, this call only.
check_onlyboolean–Dry run: write nothing, return the `candidates` this add would be refused for.
idstring–Re-record an existing memory under its id -- how a fact is CORRECTED. Omit for a new one.
relationstring–Answer to a 'possible duplicate' refusal: new | extends:ID | duplicate_of:ID | related:ID (the refusal lists candidates and options). Omit at first.
tagsstring–Comma-separated tags, e.g. 'gpu,machine'.
textstringyesThe fact, in one or two sentences.

No output schema declared.

No examples provided.

Common questions

What is the ddflow MCP server?

ddflow is an MCP server listed in the public MCP registry as io.github.delian/ddflow-mcp. Work-queue kernel for AI coding agents: dependencies, worktree isolation, quality gates, recovery. This page covers its PyPI package (ddflow-mcp).

Is the ddflow MCP server safe to use?

ddflow scores 49 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 5 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the ddflow MCP server expose?

ddflow exposes 106 tools: ddflow_abandon, ddflow_bisect, ddflow_block, ddflow_board, ddflow_brief, and 101 more. Their descriptions and schemas cost roughly 16,898 tokens of context every time the server is loaded.

Is the ddflow MCP server still maintained?

ddflow is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the ddflow MCP server under?

ddflow declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.