ddflow
PYPI · DDFLOW-MCP · 3 COMPONENTS · SCANNED OCT 5
Work-queue kernel for AI coding agents: dependencies, worktree isolation, quality gates, recovery
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security100
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- Runs hatchling.build at install time, a recognised build step with no custom scripting around it. View diagnostics → Pass
- 0 of 2 dependencies flagged as unhealthy. View diagnostics → Pass
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to delian/ddflow-mcp). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 0 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability0
- Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Stability & Change Management0
- Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.Unverified
Tool Coverage0
- Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.Unverified
Tool Safety0
- Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.Unverified
Capabilities0
- Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet.Unverified
Unverified: 5 categories
Categories scored 0 because our sandbox has not given us the schema these checks need to read. That is a gap on our side rather than a finding about the package, and we only credit what we can confirm, so the score stands at 0 until the capture succeeds. We are working through the fleet, so this normally clears without any action from you. How we score packages →
How do I install the ddflow MCP server?
ddflow runs locally as a PyPI package, launched with uvx ddflow-mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
pypi · ddflow-mcp
claude mcp add delian-ddflow-mcp -- uvx ddflow-mcp
{
"mcpServers": {
"delian-ddflow-mcp": {
"command": "uvx",
"args": [
"ddflow-mcp"
]
}
}
} {
"servers": {
"delian-ddflow-mcp": {
"command": "uvx",
"args": [
"ddflow-mcp"
]
}
}
} codex mcp add delian-ddflow-mcp -- uvx ddflow-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"delian-ddflow-mcp": {
"type": "local",
"command": [
"uvx",
"ddflow-mcp"
],
"enabled": true
}
}
} openclaw mcp add delian-ddflow-mcp --command uvx --arg ddflow-mcp
mcp_servers:
delian-ddflow-mcp:
command: "uvx"
args: ["ddflow-mcp"] {
"McpServers": {
"delian-ddflow-mcp": {
"Transport": "stdio",
"Command": "uvx",
"Arguments": [
"ddflow-mcp"
]
}
}
} assistant mcp add delian-ddflow-mcp -t stdio -c uvx -a ddflow-mcp
{
"mcpServers": {
"delian-ddflow-mcp": {
"command": "uvx",
"args": [
"ddflow-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 5 Oct 26 +5
- Source repository: unverified → pass ▲ security
- Package version: 0.1.11 → 0.1.13 functional
- 4 Oct 26 −20
- Provenance: pass → unverified ▼ security
- Stability: 0.03 → unverified ▼ security
- Tool safety: pass → unverified ▼ security
- Malware scan: unverified → pass ▲ security
- Schema quality: 100 → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- Capabilities: fail → unverified ▼ functional
- Schema quality: 190 → 157 ▲ functional
- Package version: 0.1.11 → 0.1.13 functional
- Package version: 0.1.11 → 0.1.12 functional
- 3 Oct 26 0
- Malware scan: unverified → pass ▲ security
- Stability: unverified → 0.03 ▲ functional
- Package version: 0.1.10 → 0.1.11 functional
- 2 Oct 26 64
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 7 Oct 2026 · Analysed pypi/ddflow-mcp@0.1.18
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | pypi |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | delian/ddflow-mcp |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/delian/ddflow-mcp/.github/workflows/publish.yml@refs/heads/main |
| Rekor log index | 3107963531 |
| Predicate type | PyPI publish attestation https://docs.pypi.org/attestations/publish/v1 |
| Subject digest | sha256:e6676e0f43f9bd0bcc9867af867c669502f1fa1f7cdbf5fcc8ad53b6ceadf680 |
Background: How many MCP packages publish verified provenance →
Install scripts 1 script
| Hook | Tier | Command |
|---|---|---|
| build_backend | allowlisted | hatchling.build |
Background: Why install scripts are a supply-chain risk →
Dependencies 2 packages
| Packages resolved | 2 |
|---|---|
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
ddflow_memory_forget ~99
Stop believing a memory that is no longer true. It is kept, with the reason: 'we thought X until Y' is what stops the next agent re-learning X. Correct a fact instead with ddflow_memory_add and its id.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| id | string | yes | Memory id. |
| reason | string | yes | Why it is no longer true. |
No output schema declared.
No examples provided.
ddflow_memory_list ~116
The project's operational memories, newest first -- or ranked against `query`. What an agent must know before touching anything on this machine; read them at session start if ddflow_brief truncated the list.
| Name | Type | Req | Description |
|---|---|---|---|
| all | boolean | – | Include forgotten memories, with why they were forgotten. |
| as_agent | string | – | A subagent's own name, this call only. |
| limit | integer | – | At most this many (default: all). |
| query | string | – | Rank by relevance to this instead of by recency. |
No output schema declared.
No examples provided.
ddflow_merge ~289
Land an item's branch without ever switching a checkout's branch. With [flow].integration = 'pr' it pushes and opens (or updates) a pull request instead, releases your lease and parks the item in REVIEW — take the next item; `ddflow_pr_sync` completes it once a person merges it.
| Name | Type | Req | Description |
|---|---|---|---|
| allow_dirty | boolean | – | Merge although the worktree has uncommitted changes; they are NOT included. Pass it only once you have looked at what is dirty and decided it is build output. |
| allow_empty | boolean | – | Land a branch with no commits ahead of its target. Refused by default: usually the item is bound to the wrong tree (rebind with ddflow_update worktree). |
| as_agent | string | – | A subagent's own name, this call only. |
| branch | string | – | For an item claimed with no_worktree: the branch to land (default: the branch checked out where this connection runs). Changes outside the item's globs come back as outside_globs. |
| id | string | yes | Item id. |
| keep | boolean | – | Keep the worktree after merging, for inspection. |
| message | string | – | Merge commit message. |
| model | string | – | The AUTHOR's model. In PR mode the item completes later, at `ddflow_pr_sync`, and the reviewer-independence check needs it then. |
No output schema declared.
No examples provided.
ddflow_next ~124
What may be started RIGHT NOW, and for everything that may not, the reason. Independent items in the ready set can be run in parallel worktrees by separate agents. Returns ready=[] when nothing is actionable — that is a result, not an error, and it never means 'pick something anyway'.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| kind | string | – | 'task' (default) or 'phase'. |
| phase | string | – | Restrict to one phase (the 'implement phase X' entry point). |
No output schema declared.
No examples provided.
ddflow_phase_add ~349
Add a phase to the queue. A phase is a unit of REVIEW: it gets its own research, its own whole-phase test pass and live smoke run, and it merges as one coherent feature. Group tasks into a phase when they only make sense shipped together.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| body | string | – | Detail, acceptance criteria, context. |
| check_only | boolean | – | Dry run: write nothing, return the `candidates` this add would be refused for. |
| globs | string | – | Comma-separated path globs this phase writes: what lets two agents work different phases in parallel; the phase's dependencies are INHERITED by every task in it. |
| id | string | yes | Short stable id, e.g. 'P2' or 'auth'. |
| line | string | – | Release line this lands on (a name from [flow.lines], or the current line). Omit for the current line; tasks inherit a phase's line. |
| needs | string | – | Comma-separated ids this phase depends on. |
| priority | integer | – | Lower is offered first (default 100). |
| readd | boolean | – | File a REMOVED item's id again with this definition. An id still in the queue is always refused -- change that item with ddflow_update. |
| relation | string | – | Answer to a 'possible duplicate' refusal: new | extends:ID | duplicate_of:ID | related:ID (the refusal lists candidates and options). Omit at first. |
| tags | string | – | Comma-separated tags. |
| title | string | – | One-line description. |
No output schema declared.
No examples provided.
ddflow_pins ~199
BEFORE compressing or rewording an instruction file (a rulebook, a driver, AGENTS.md, CLAUDE.md, a prompt template): which of its text a test pins, which suites to re-run afterwards, and the longest stretches no test holds. A sentence that reads like rationale is often a rule a test asserts. Exit 2: no Python suite to read pins from -- then treat ALL of it as pinned. Free text is a lower bound, not permission.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| document | string | yes | Path of the instruction file, relative to the repo. |
| min_needle | integer | – | Shortest string literal that counts as a pin (default 12). |
| tests | string | – | Comma-separated test dirs (default: tests,test). |
| top | integer | – | How many free stretches to return (default 10). |
No output schema declared.
No examples provided.
ddflow_pr_status ~68
Every item's pull request as last recorded — review, checks, target, rounds of changes and when it was last looked at. Reads the log only; `ddflow_pr_sync` asks the forge.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
No output schema declared.
No examples provided.
ddflow_pr_sync ~151
Ask the forge (GitHub/GitLab) what reviewers did with every request in REVIEW and record it: a merged request completes its item (and retargets what is stacked on it), requested changes return the item to the queue WITH the review text, a closed one is parked for a person, an approved green one is merged when [flow].pr_merge = 'on_approval'. `ddflow_next` does this itself with [flow].sync_on_next. Exit 2: the forge could not be asked -- NOT 'nothing changed'.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| item | string | – | Only this item (optional). |
No output schema declared.
No examples provided.
ddflow_pr_threads ~115
An item's review threads, read live from the forge. With `thread`, `reply` on it and/or `resolve` it, so the reviewer sees what was addressed. Exit 2 = forge not reached; 3 = refused.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| id | string | yes | The item. |
| reply | string | – | Reply text. |
| resolve | boolean | – | Resolve it. |
| thread | string | – | Thread id, as listed. |
No output schema declared.
No examples provided.
ddflow_precommit ~184
A .pre-commit-config.yaml proposed for THIS repository: its stacks (Python, shell, Docker, JS, Go, Rust; YAML/TOML/JSON checks) mapped to pinned hooks, plus ddflow's check-commit and check-msg as local hooks, so pre-commit owns .git/hooks/ (remove ddflow's own first; the body names them). Proposes; installs nothing. `write` creates the file, REFUSED (exit 3) when one exists. The body names missing programs. Installing pre-commit is the operator's call.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| ddflow_cmd | string | – | How the local hooks reach ddflow (default `ddflow` on PATH). |
| write | boolean | – | Create the file; never replaces an existing one. |
No output schema declared.
No examples provided.
ddflow_progress ~128
What work has ACTUALLY been done, aggregated from the event log: attempts per item, wall-clock held, gate runs, commits produced, and who did them. Use it to answer 'how much effort has gone into this' and to see an item's full gate history including the outcomes that were not passes.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| id | string | – | One item, with its per-attempt detail. |
| limit | integer | – | Rows returned, most effort first (default 25; 0 = all). |
No output schema declared.
No examples provided.
ddflow_promote_add ~119
File a PROMOTION to an environment branch ([flow].environments): a task that merges the branch immediately upstream into it, runs the promotion pipeline and lands by merge or request -- always one step downstream. Exit 2 = nothing to promote; exit 3 = refused (unknown environment, one open, branch missing).
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| env | string | yes | The environment to promote TO. |
| force | boolean | – | File it even with nothing to carry. |
No output schema declared.
No examples provided.
ddflow_promote_deployed ~83
Record the sha a deploy put LIVE in an environment (from the deploy hook); promote_status then shows what runs there. Exit 3 = refused.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| env | string | yes | Environment. |
| sha | string | – | Deployed commit (default: branch head). |
No output schema declared.
No examples provided.
ddflow_promote_status ~58
Each environment: head, commits behind its upstream, open promotion, auto_promote, and the live (deployed) sha. Reads only.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
No output schema declared.
No examples provided.
ddflow_prompts ~125
Inspect the prompt templates this project uses, and where each comes from (shipped default, project override, or an explicit config path). Use `eject` to copy the shipped ones into .ddflow/prompts/ so the project can edit them as plain text — reviewer instructions and workflow commands are operator-tunable behaviour, not code.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | – | list (default), show, or eject. |
| as_agent | string | – | A subagent's own name, this call only. |
| name | string | – | Template name, for show/eject. |
No output schema declared.
No examples provided.
ddflow_rebuild ~54
Re-derive the search index from the event log. The index is a disposable cache; this is never a data-loss operation.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
No output schema declared.
No examples provided.
ddflow_recall ~227
'HAVE WE BEEN HERE BEFORE?' -- one search across everything this project remembers: decisions, lessons, research verdicts, operational memories, past bugs, similar tasks and the operator's earlier prompts. CALL THIS BEFORE STARTING ANY NON-TRIVIAL WORK, so nothing is said or learned twice. Results are labelled by kind (a binding decision, a transferable lesson and an old prompt change what you do differently); a superseded decision names its replacement -- follow that.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| limit | integer | – | Hits per source (default 3). |
| max_chars | integer | – | Total budget for the answer. The point of a budget is that recall is called at the START of work, where a long answer costs the context the work itself needs. |
| query | string | yes | What you are about to do, in plain words. |
| sources | string | – | Comma-separated subset: decisions,lessons,memories,research,bugs,items,prompts. Default: all. |
No output schema declared.
No examples provided.
ddflow_recover ~139
Find work left behind by a crashed agent: expired leases, orphaned worktrees, items stuck running. Reports what each worktree contains and never deletes anything. Run this at the start of any session that follows an interruption.
| Name | Type | Req | Description |
|---|---|---|---|
| apply | boolean | – | Act on the advice: release the leases and remove the worktrees reported as holding nothing. Only a tree MEASURED as having no uncommitted and no unmerged work is touched; 'could not tell' is not 'emp… |
| as_agent | string | – | A subagent's own name, this call only. |
| item | string | – | Restrict to one item. |
No output schema declared.
No examples provided.
ddflow_release ~96
Give up a lease without completing the item — when you are handing off, stopping, or recovering someone else's abandoned work after inspecting it. The note is recorded in the log and is often the only lasting explanation of why a claim was broken.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| id | string | yes | Item id. |
| note | string | – | Why you are releasing it. |
No output schema declared.
No examples provided.
ddflow_remove ~138
Take an item out of the queue. The log is append-only, so this RECORDS a removal rather than erasing anything — the item stays in the history and in replay, which keeps the record honest about work that was planned and then dropped. Refuses if another item depends on it.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| force | boolean | – | Remove although it still has open children or dependents. Both leave the queue inconsistent in a way the scheduler reports; read the refusal before overriding. |
| id | string | yes | Item id. |
| reason | string | – | Why. |
No output schema declared.
No examples provided.
ddflow_render ~107
Regenerate the human-readable markdown views (queue, lessons, the one-paragraph lessons summary, research) under docs/ddflow/.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| out | string | – | Directory for the generated views (default: docs/ddflow). |
| show | string | – | Print ONE view instead of writing files: lessons, lessons-summary, research, or board. This is what the ddflow:// resources are served from. |
No output schema declared.
No examples provided.
ddflow_replay ~142
Reconstruct the project's whole decision history from the log: every operator prompt in order, every architectural decision, every research verdict, every lesson, and the shape of the queue. This is what rebuilds the project if the code is lost — it reproduces the DECISIONS, not the bytes.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| out | string | – | Write a recovery kit to this directory. |
| verify | boolean | – | Re-resolve every recorded commit sha against this repository and report the ones that are gone: a reconstruction citing unresolvable shas is a narrative, not a record. |
No output schema declared.
No examples provided.
ddflow_research_add ~366
Record a research finding. verdict MUST be CONFIRMED, REFUTED or THEORETICAL, and CONFIRMED/REFUTED require a probe — a verdict with no probe behind it is an opinion. A REFUTED entry is as valuable as an adopted one: it stops the next session re-researching it.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| budget | string | – | What you allowed yourself, e.g. '30 min, no GPU'. |
| check_only | boolean | – | Dry run: write nothing, return the `candidates` this add would be refused for. |
| claim | string | – | The falsifiable claim. |
| falsifier | string | – | The single observation that would kill it. |
| id | string | – | Stable id you choose. Referenced by `supersedes`, by commit messages and by the reconstruction; a generated id cannot be cited in advance. |
| item | string | – | The task this research is for. |
| mechanism | string | – | WHY it would work in this repo. The middle field of the triple — claim, mechanism, falsifier — and the one most often skipped. |
| probe | string | – | The command you ran. |
| probe_output | string | – | Its output, verbatim. |
| question | string | yes | What was asked. |
| relation | string | – | Answer to a 'possible duplicate' refusal: new | extends:ID | duplicate_of:ID | related:ID (the refusal lists candidates and options). Omit at first. |
| sources | string | – | Comma-separated URLs/DOIs you actually opened. |
| verdict | string | yes | CONFIRMED | REFUTED | THEORETICAL |
No output schema declared.
No examples provided.
ddflow_resolve ~231
Settle a CONTESTED item: two clones each added the same id with different content, or each claimed it, and a merge brought both in (`ddflow_doctor` names them, `ddflow_show` lists the rivals, `ddflow_next` withholds them). `keep` names the definition (event id or agent) and/or the lease holder to keep; the losing claim is released in the same transaction; a losing DEFINITION comes back in `lost`: re-add it under a new id with `refile_as`, or it stays only in the log. Refused (exit 3) when not contested.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| id | string | yes | The contested item. |
| keep | string | yes | Event id (or a 6+ character prefix), agent, or lease holder to keep. |
| refile_as | string | – | Comma-separated new ids, one per definition NOT kept, in `show` order: each is re-added under its new id in the same transaction. |
No output schema declared.
No examples provided.
ddflow_review ~345
Run the configured cross-family reviewer over an item's diff and record the result: the critic gate, performed by ddflow. No reviewer, endpoint or verdict records UNAVAILABLE, never a pass. A gate gets [review].max_rounds (default 2) full rounds, then delta=true and ddflow_review_triage.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| base | string | – | Ref to diff against (default: the base branch). |
| branch | string | – | Review this branch against base, for an item claimed with no_worktree (default: the branch checked out where this connection runs). With neither, the review is recorded unavailable. |
| chunk | array | – | Re-review ONLY these chunk numbers (as the recorded review numbered them, e.g. [5]) and merge into that record; needs the same diff, chunk size and reviewer. |
| commit | string | – | Review this ONE landed commit (against its first parent) instead of the item's branch: the after-merge review, when the branch is gone. |
| context | string | – | Extra context for the reviewer. |
| delta | boolean | – | Recheck only what changed since the reviewed head. |
| full | boolean | – | Force a full round (else a delta once reviewed). |
| gate | string | – | Gate: critic (default) or rubber_duck. |
| id | string | yes | Item whose diff to review. |
| intent | string | – | What the change is MEANT to do. The reviewer flags where the diff and the intent disagree, so without it there is nothing to disagree with. Defaults to the item's title and body. |
No output schema declared.
No examples provided.
ddflow_review_triage ~208
Record your triage of ONE finding of an item's recorded `ddflow review`: it is refuted (probe = the run that shows it false) or confirmed (probe = the fix or test that answers it). The finding number is the #N the review printed. The gate stays failed -- a review that reported findings is not re-recorded as passed; the log shows each finding's fate instead (decision D-review-triage).
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| finding | integer | yes | The finding's number: #N in the review's output -- of the RECORDED reviewer's findings, which the output's last lines name when several ran. |
| gate | string | – | Omit if one gate has findings. |
| id | string | yes | The item whose review it is. |
| probe | string | yes | The evidence for the verdict. Required. |
| verdict | string | yes | refuted or confirmed. |
No output schema declared.
No examples provided.
ddflow_reviewers_detect ~175
Probe well-known local ports for an OpenAI-compatible model server (ollama, vLLM, LM Studio, llama.cpp, sglang) and report what serves, with each model's pretraining family: how to find a reviewer from a DIFFERENT family than yourself, which the critic gate requires. write=true records it in the git-ignored .ddflow/local/reviewers.toml (this machine's, never committed).
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| shared | boolean | – | With write: commit them to .ddflow/config.toml instead, for every clone. Only for a reviewer the whole team reaches at the same address. |
| write | boolean | – | Append the discovered reviewers to .ddflow/local/reviewers.toml. |
No output schema declared.
No examples provided.
ddflow_reviewers_list ~42
Show the configured reviewers, their families and which gates they serve.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
No output schema declared.
No examples provided.
ddflow_rule_add ~229
Add a project rule; duplicate-checked like every add (answer new | extends:ID | duplicate_of:ID | related:ID).
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| check | boolean | – | Dry run: list duplicates only. |
| content | string | – | Rule text (may be empty for check_only). |
| duplicate_of | string | – | Dedup answer: same as record ID. |
| extends | string | – | Dedup answer: extends record ID. |
| globs | string | – | Comma-separated globs it governs. |
| id | string | yes | Rule id, e.g. r-naming. |
| new | boolean | – | Dedup answer: a different record. |
| priority | integer | – | Priority 0-100 (default 50). |
| related | string | – | Dedup answer: related to ID. |
| scope | string | – | project (default) | phase | task | global. |
| tags | string | – | Comma-separated tags. |
| title | string | yes | One-line rule statement. |
No output schema declared.
No examples provided.
ddflow_rule_edit ~115
Change fields of an existing rule; omitted fields stay. Recorded in the manifest.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| content | string | – | New content. |
| globs | string | – | Comma-separated globs. |
| id | string | yes | Rule id to edit. |
| priority | integer | – | New priority. |
| scope | string | – | New scope. |
| tags | string | – | Comma-separated tags. |
| title | string | – | New title. |
No output schema declared.
No examples provided.
ddflow_rule_list ~89
List the project's rules, filtered by tag or scope: what governs the current work.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| json | boolean | – | JSON array. |
| limit | integer | – | Maximum results (default 100). |
| scope | string | – | Filter by this scope. |
| tag | string | – | Filter by this tag. |
No output schema declared.
No examples provided.
ddflow_rule_remove ~68
Delete a rule from the manifest; the removal is logged as an event.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| id | string | yes | Rule id to remove. |
| reason | string | – | Why it is removed (recorded). |
No output schema declared.
No examples provided.
ddflow_rule_search ~117
Search rules by title or content, ranked by relevance, for an area or topic.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| exact | boolean | – | Exact phrase. |
| limit | integer | – | Maximum results to return (default 10). |
| query | string | yes | Search query (keywords or regex). |
| regex | boolean | – | Query is a regex. |
| scope | string | – | Filter results by this scope. |
| tag | string | – | Filter results by this tag. |
No output schema declared.
No examples provided.
ddflow_rule_show ~61
One rule with all its metadata: title, content, tags, scope, priority, globs, timestamps.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| id | string | yes | Rule id to retrieve. |
No output schema declared.
No examples provided.
ddflow_session_end ~86
Close a session with a summary of what it achieved. The summary is what a later reader sees before deciding whether to open the whole transcript, so write it for someone who was not there.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| session | string | yes | Session id. |
| summary | string | – | What this session achieved. |
No output schema declared.
No examples provided.
ddflow_session_note ~114
Record something that happened during a session which is neither an operator prompt nor a decision — a surprise, a dead end, why you changed approach. It goes into the reconstruction alongside the prompts, and a dead end recorded is a dead end nobody walks down twice.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| item | string | – | Item it concerns. |
| session | string | – | Session id; omit for the latest open. |
| text | string | yes | The note. |
No output schema declared.
No examples provided.
ddflow_session_prompt ~107
Record the operator's prompt verbatim. This is what makes the project reconstructible from the log alone if everything else is lost. Secrets are redacted before anything touches disk. Call it once per operator turn.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| item | string | – | Item it concerns. |
| session | string | – | Session id; omit for the latest open. |
| text | string | yes | The prompt, verbatim. |
No output schema declared.
No examples provided.
ddflow_session_start ~67
Open a session for provenance logging. Returns the session id.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| model | string | – | Your model id. |
| tool | string | – | Your harness, e.g. 'claude-code'. |
No output schema declared.
No examples provided.
ddflow_setup ~231
Install ddflow into this repository: creates .ddflow/, writes the driver and the AGENTS.md section, and registers nothing else. Run this ONCE per project, then set your test command with ddflow_configure. Safe to re-run — it updates a managed block and leaves your own prose alone.
| Name | Type | Req | Description |
|---|---|---|---|
| agents | string | – | Comma-separated agents to write driver deltas for: claude,gemini,codex,copilot,vscode,kilo,cursor,kimi,opencode,glm,qwen,antigravity,devin,qodo,tabnine,aider,cline,windsurf,replit,openhands,goose,cod… |
| as_agent | string | – | A subagent's own name, this call only. |
| refresh_docs | boolean | – | Rewrite ONLY the driver docs, AGENTS.md/CLAUDE.md blocks and adopted agents' native rules from this ddflow's templates (no MCP, hook or command-file changes), e.g. when ddflow_doctor notes drift. Ref… |
No output schema declared.
No examples provided.
ddflow_show ~106
Everything known about one phase, task or bug (a bug id works too): state, dependencies, declared globs, the lease and who holds it, the worktree path you can cd to, and every gate's outcome with its evidence. Use it to check your own work before calling ddflow_complete.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| id | string | yes | Item id (phase, task) or bug id. |
No output schema declared.
No examples provided.
ddflow_similar ~191
'IS THIS ALREADY FILED?' -- the existing records most like a text, BEFORE you file it as a bug, task, lesson or other record. Read-only. Candidates cross kinds and include closed records (a bug that repeats a fixed one is caught); each carries id, kind, title, state, score (0-1), shared words and flags, per [dedupe] show_floor, max_candidates and kinds. A score is a prompt to LOOK, not a verdict. Nothing close: exit 2.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| kind | string | – | Comma-separated subset of the configured kinds to look in: bug,task,phase,lesson,decision,research,memory. Default: all of them. |
| text | string | yes | The title or summary of the record you are about to file. |
No output schema declared.
No examples provided.
ddflow_split ~195
Split an item into sub-tasks IN PLACE when the work turns out to be two things -- the moment you discover it; mid-task discovery is normal. The original keeps its id and history and becomes an umbrella that completes when its children do; closing it and opening two new ones would lose the thread between what was planned and what happened. Children inherit the parent's globs: give each its own afterwards if they write different files, or they cannot run in parallel.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| globs | string | – | Globs for the children (default: inherit). |
| id | string | yes | The item to split. |
| into | string | yes | Comma-separated 'sub-id=title' pairs. At least two. |
| needs | string | – | Dependencies for the FIRST child. The others chain from it if you set theirs with ddflow_update. |
No output schema declared.
No examples provided.
ddflow_status ~106
The state of the whole project in one answer: how many tasks are done and which, what is in flight and who holds it, what is ready to start, what is blocked, how many agent-hours and commits went in, and whether anything is looping or waiting to be recovered. This is the tool for 'what is the status of this project?' and 'what has been completed?'.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
No output schema declared.
No examples provided.
ddflow_task_add ~445
Add a task to a phase. ALWAYS set globs to the paths this task will write: they are what lets two agents work in parallel safely, and an unset glob means the conflict detector cannot protect you.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| body | string | – | Detail and acceptance criteria. |
| check_only | boolean | – | Dry run: write nothing, return the `candidates` this add would be refused for. |
| globs | string | – | Comma-separated path globs this task writes. |
| id | string | yes | Short stable id, e.g. 'P2.T1'. |
| line | string | – | Release line this lands on (a name from [flow.lines], or the current line). Omit for the current line; tasks inherit a phase's line. |
| lines | string | – | Release lines a FIX must reach, e.g. '1,2,3': written where [flow].port_strategy says, plus a port task `<id>@<line>` per other line. |
| needs | string | – | Comma-separated ids this task depends on. |
| parent | string | – | Owning phase id, OR another TASK's id, which makes this a SUB-TASK with its own globs and dependencies, run in parallel with its siblings. Same field as `phase` (the CLI has both names). |
| phase | string | – | Owning phase id. Give this OR `parent`. |
| port_of | string | – | Earlier fix this follows up: reuses the lines it reached. |
| priority | integer | – | Lower is offered first (default 100). |
| readd | boolean | – | File a REMOVED item's id again with this definition. An id still in the queue is always refused -- change that item with ddflow_update. |
| relation | string | – | Answer to a 'possible duplicate' refusal: new | extends:ID | duplicate_of:ID | related:ID (the refusal lists candidates and options). Omit at first. |
| tags | string | – | Comma-separated tags. |
| title | string | – | One-line description. |
No output schema declared.
No examples provided.
ddflow_tests ~150
AFTER EACH CHANGE: the tests your change reaches (changed tests, tests importing a changed module directly or one step removed, tests named after it, a changed conftest's), each with why, and a command running them IN PARALLEL. Run it; do not reason about which matter. Never a pass: unit_tests runs the WHOLE suite. `item`: diff that item's worktree. Exit 2: no test reaches the change.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| base | string | – | Compare against this ref instead of the item's base. |
| item | string | – | The item whose worktree and base to use. |
No output schema declared.
No examples provided.
ddflow_unblock ~148
Release a BLOCKED item -- and every blocked item beneath it -- back into the queue, so `next` can offer them again. The inverse of ddflow_block, and how deferred work, or a whole archived section an import landed as blocked, becomes work once the OPERATOR says so: pass a phase id to release its section. Do not release held work on your own judgement. Returns nothing-to-do (exit 2) when nothing there is blocked.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| id | string | yes | Item id. |
| note | string | – | Why it is work again (who decided, and when). |
No output schema declared.
No examples provided.
ddflow_update ~353
Change an item's fields. MOST IMPORTANT USE: widening `globs` when your work turns out to touch files outside what you claimed. Do that BEFORE writing them: the conflict detector and commit hook work from the declared globs, so an undeclared file is unprotected and the commit is refused.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| body | string | – | New detail / acceptance criteria. |
| globs | string | – | Path globs this item writes, comma-separated or a JSON array. REPLACES the list (a claimed item's lease too); the result names what it dropped. |
| id | string | yes | Item id. |
| line | string | – | Move it to another release line. |
| needs | string | – | Comma-separated ids it depends on. Pass an EMPTY string to clear them — that is how you break a dependency cycle the loop detector found. |
| priority | integer | – | Lower is offered first (default 100). |
| resources | string | – | Physical resources the work RUNS on, beside its files: 'gpu:4,vllm-fleet'. `next` withholds and `claim` refuses while live claims use up the capacity ([schedule] resources). Declare for a GPU job, mo… |
| tags | string | – | Comma-separated tags. |
| title | string | – | New title. |
| worktree | string | – | Rebind the item and your live lease to this linked worktree (absolute, or repo-relative) and its branch: the way out of a wrong-tree binding, since re-claiming keeps the recorded tree and merge lands… |
No output schema declared.
No examples provided.
ddflow_verify ~166
Re-check a done task's claims; fails if one does not hold. No id: sweep all, worst first.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| file_bugs | boolean | – | File a bug per failing completion. |
| force | boolean | – | Reopen even if it holds. |
| id | string | – | Task id; omit to sweep. |
| judge | boolean | – | Cross-family reviewer judges it. |
| limit | integer | – | How many of the worst to list (20). |
| pack | boolean | – | Evidence pack for a verifier. |
| phase | string | – | Sweep only this phase. |
| reason | string | – | Why (reopen). |
| reopen | boolean | – | Reopen a failing completion. |
No output schema declared.
No examples provided.
ddflow_version_cut ~179
Tag the next version. trunk: tags the base branch. gitflow: release/X from develop, merged to production, tagged, tag merged back; with pull requests, opens the release request (`ddflow_pr_sync` tags it once merged). Exit 2 = nothing to release.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| bump | string | – | major | minor | patch. |
| changelog | boolean | – | Also write CHANGELOG.md. |
| dry_run | boolean | – | Report only. |
| force | boolean | – | Overwrite a hand-edited file. |
| line | string | – | A maintenance line: tagged where it stands; its major is kept. |
| push | boolean | – | Publish the tag and branches. |
| version | string | – | MAJOR.MINOR.PATCH. |
No output schema declared.
No examples provided.
ddflow_version_show ~109
The current version (highest `<tag_prefix>X.Y.Z` tag reachable from the release branch), the next one, the bump and why (Conventional Commits plus the tags of finished items), and the release notes. Reads only.
| Name | Type | Req | Description |
|---|---|---|---|
| as_agent | string | – | A subagent's own name, this call only. |
| bump | string | – | Force major | minor | patch instead of the computed bump. |
| line | string | – | A maintenance line (default: the current one). |
No output schema declared.
No examples provided.
What is the ddflow MCP server?
ddflow is an MCP server listed in the public MCP registry as io.github.delian/ddflow-mcp. Work-queue kernel for AI coding agents: dependencies, worktree isolation, quality gates, recovery. This page covers its PyPI package (ddflow-mcp).
Is the ddflow MCP server safe to use?
ddflow scores 49 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 5 October 2026. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the ddflow MCP server expose?
ddflow exposes 106 tools: ddflow_abandon, ddflow_bisect, ddflow_block, ddflow_board, ddflow_brief, and 101 more. Their descriptions and schemas cost roughly 16,898 tokens of context every time the server is loaded.
Is the ddflow MCP server still maintained?
ddflow is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the ddflow MCP server under?
ddflow declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.