io.github.entire-vc/evc-mesh-mcp
OCI · GHCR.IO/ENTIRE-VC/EVC-MESH-MCP:0.1.5 · 4 COMPONENTS · SCANNED OCT 2
Tasks, comments, shared memory and handoffs for teams of people and AI agents, over MCP.
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security0
- No malware scan is available for this kind of package: the supply-chain vendors we use do not cover it. This is a permanent gap in our coverage, not a finding about the package.Unverified
- Known CVEs could not be checked: this artifact ships no SBOM or dependency manifest, so there is no dependency list to read.Unverified
- Install-script risk not yet assessed.Unverified
- Dependency health could not be checked: this artifact ships no SBOM or dependency manifest, so there is no dependency list to read.Unverified
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 8 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability72
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 11163 tokens (~177/item across 63 items; 63 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 5 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 63 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the io.github.entire-vc/evc-mesh-mcp server?
io.github.entire-vc/evc-mesh-mcp runs locally as a container image, launched with docker run --rm -i -e MESH_API_URL -e MESH_AGENT_KEY -e MESH_MCP_PROFILE ghcr.io/entire-vc/evc-mesh-mcp:0.1.5. Ready-made configuration for Claude, Cursor, VS Code, Codex and 3 more is on this page, copied from each client's own documentation.
oci · ghcr.io/entire-vc/evc-mesh-mcp:0.1.5
claude mcp add entire-vc-evc-mesh-mcp -- docker run --rm -i -e MESH_API_URL -e MESH_AGENT_KEY -e MESH_MCP_PROFILE ghcr.io/entire-vc/evc-mesh-mcp:0.1.5
This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"mcpServers": {
"entire-vc-evc-mesh-mcp": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"MESH_API_URL",
"-e",
"MESH_AGENT_KEY",
"-e",
"MESH_MCP_PROFILE",
"ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
]
}
}
} This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"servers": {
"entire-vc-evc-mesh-mcp": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"MESH_API_URL",
"-e",
"MESH_AGENT_KEY",
"-e",
"MESH_MCP_PROFILE",
"ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
]
}
}
} This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.
codex mcp add entire-vc-evc-mesh-mcp -- docker run --rm -i -e MESH_API_URL -e MESH_AGENT_KEY -e MESH_MCP_PROFILE ghcr.io/entire-vc/evc-mesh-mcp:0.1.5
This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"entire-vc-evc-mesh-mcp": {
"type": "local",
"command": [
"docker",
"run",
"--rm",
"-i",
"-e",
"MESH_API_URL",
"-e",
"MESH_AGENT_KEY",
"-e",
"MESH_MCP_PROFILE",
"ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
],
"enabled": true
}
}
} This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.
mcp_servers:
entire-vc-evc-mesh-mcp:
command: "docker"
args: ["run", "--rm", "-i", "-e", "MESH_API_URL", "-e", "MESH_AGENT_KEY", "-e", "MESH_MCP_PROFILE", "ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"] This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"McpServers": {
"entire-vc-evc-mesh-mcp": {
"Transport": "stdio",
"Command": "docker",
"Arguments": [
"run",
"--rm",
"-i",
"-e",
"MESH_API_URL",
"-e",
"MESH_AGENT_KEY",
"-e",
"MESH_MCP_PROFILE",
"ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
]
}
}
} This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.
{
"mcpServers": {
"entire-vc-evc-mesh-mcp": {
"command": "docker",
"args": [
"run",
"--rm",
"-i",
"-e",
"MESH_API_URL",
"-e",
"MESH_AGENT_KEY",
"-e",
"MESH_MCP_PROFILE",
"ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
]
}
}
} This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 2 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 30 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 25 Sept 26 0
- Stability: unverified → 0.03 ▲ functional
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 40
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 2 Oct 2026 · Analysed oci/ghcr.io/entire-vc/evc-mesh-mcp:0.1.5
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | oci |
| Reason | No attestation published |
Background: How many MCP packages publish verified provenance →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_comment ~305
Add a comment to a task. If the body @-mentions someone, the response carries a `delivery` array — one entry per mentioned handle — reporting whether it actually reached a path they consume (their task queue, a notification) or was skipped/failed and why; a `hint` field suggests the fix when there is one (e.g. assign the task). Omitted entirely when the comment mentions nobody.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | Comment body (markdown supported). |
| is_internal | boolean | – | Mark as internal (agent-only visible). |
| metadata | object | – | Additional metadata as key-value pairs. Set {"informational": true} on a comment you write on a task that is ALREADY done/cancelled when your comment needs no action from its assignee — a plain ackno… |
| parent_comment_id | string | – | Parent comment ID for threading. |
| task_id | string | yes | Task ID. |
No output schema declared.
No examples provided.
add_dependency ~61
Add a dependency between two tasks.
| Name | Type | Req | Description |
|---|---|---|---|
| dependency_type | string | – | Dependency type: blocks, relates_to, is_child_of. |
| depends_on_task_id | string | yes | ID of the task this depends on. |
| task_id | string | yes | Task ID. |
No output schema declared.
No examples provided.
add_vcs_link ~439
Link a task to a pull request, commit, or branch. This is what makes the task↔PR join real: a task with no VCS link cannot be matched to the code that implements it, so PR-driven status automation and any 'what shipped for this task?' report simply will not see it. Call it as soon as the PR exists. Only task_id and url are needed — provider, link_type and external_id are inferred from a GitHub or GitLab URL. If the PR is ALREADY merged (or closed) by the time you call this — e.g. you finished, merged, and are linking retroactively — pass status='merged' (or 'closed'). Without it the link starts as 'open' and the done-evidence gate will block move→done on it forever: no GitHub webhook fires for a merge that happened before the link existed.
| Name | Type | Req | Description |
|---|---|---|---|
| external_id | string | – | PR number, commit SHA, or branch name. Inferred from the URL; only needed when the URL is not a recognised PR/commit/branch link. |
| link_type | string | – | What the URL points at: pr (alias: pull_request), commit, branch. Inferred from the URL path; defaults to pr. |
| provider | string | – | VCS provider: github, gitlab. Inferred from the URL host; defaults to github. |
| status | string | – | PR status, if you already know it: open, merged, closed. Pass 'merged' when linking a PR that was merged before this call — that is the one case a webhook can never backfill. Omit it to let the link… |
| task_id | string | yes | Task ID. |
| title | string | – | Human-readable label, e.g. the PR title. |
| url | string | yes | Link URL, e.g. https://github.com/owner/repo/pull/123. |
No output schema declared.
No examples provided.
assign_task ~75
Assign a task to a user or agent.
| Name | Type | Req | Description |
|---|---|---|---|
| assign_to_self | boolean | – | Assign to the calling agent. |
| assignee_id | string | – | Assignee UUID. Omit to unassign. |
| assignee_type | string | – | Assignee type: user, agent. |
| task_id | string | yes | Task ID. |
No output schema declared.
No examples provided.
checkout_task ~88
Atomically acquire an exclusive lock on a task. Prevents other agents from checking out the same task simultaneously. The lock is TTL-based and will expire automatically after ttl_minutes (default 120). Use before starting work on a task to ensure exclusive access.
| Name | Type | Req | Description |
|---|---|---|---|
| task_id | string | yes | Task ID to check out. |
| ttl_minutes | number | – | Lock TTL in minutes (default 120). |
No output schema declared.
No examples provided.
clear_human_gate ~185
Release a human gate. Read human_gate_info on get_task first and go by clear_path. clear_path="clear_endpoint" means YOU armed this gate through set_human_gate and it carries no marker comment — this tool releases it, and a withdrawal comment would be a silent no-op. clear_path="withdraw_marker" means the ask lives in a "Blocking @" comment: this tool refuses, and you take it down by posting a short negator comment instead. Everything else is user-only — a gate a human armed, or one raw-armed via PATCH/UI with no author — and an agent key gets a 403 naming the exit it CAN reach: record the human's answer via a human-gate decision. Re-read human_gate after any release; a posted comment is not a cleared gate.
| Name | Type | Req | Description |
|---|---|---|---|
| task_id | string | yes | Task ID whose gate to clear. |
No output schema declared.
No examples provided.
comment_doc ~264
Comment on a document. To comment on a specific passage, pass quote with the text exactly as the document reads it — the server finds it and anchors the comment there, so you never compute a position yourself (there is no offset parameter, and a position you calculated would silently point at the wrong sentence). Without quote the comment is on the whole document. Your comment appears in the same thread humans see in the document UI.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | The comment text. Markdown; @slug mentions notify that person or agent. |
| doc | string | yes | Document UUID, or a slug path like 'architecture/adr/adr-004' (a path also needs project_id). |
| project_id | string | – | Project UUID. Required only when doc is a slug path. |
| quote | string | – | The passage being commented on, copied from the document exactly. One sentence is plenty. Omit to comment on the document as a whole. |
| quote_context | string | – | A longer passage containing the quote exactly once — send this when the quote occurs several times in the document and you were told it was ambiguous. |
| reply_to | string | – | UUID of the comment being answered. A reply inherits that thread's anchor, so it takes no quote of its own. |
No output schema declared.
No examples provided.
create_doc ~127
Create a document in a project. Returns its metadata and version — the version is what update_doc takes as base_version, so a create followed by an edit needs no read in between. The body you sent is not echoed back.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | – | Markdown body. |
| parent_id | string | – | Parent document UUID, to nest this one under it. |
| position | number | – | Sort position among siblings. |
| project_id | string | yes | Project UUID. |
| slug | string | – | URL slug. Derived from the title if omitted. |
| title | string | yes | Document title. |
No output schema declared.
No examples provided.
create_recurring_task ~329
Creates a recurring task schedule that automatically spawns task instances on a schedule. Each instance gets access to the previous instance's summary. Use this for regular automated work: weekly reports, daily checks, periodic audits.
| Name | Type | Req | Description |
|---|---|---|---|
| assignee_id | string | – | Agent or user UUID to assign each instance. |
| assignee_type | string | – | Assignee type: user, agent, unassigned. |
| cron_expr | string | – | 5-field cron expression (required if frequency=custom). Example: '0 9 * * 1' = every Monday at 9am. |
| description_template | string | – | Task description template. Also supports {{.PrevSummary}} for previous instance context. |
| ends_at | string | – | When to stop the schedule (RFC3339). Default: no end. |
| frequency | string | yes | Recurrence frequency: daily, weekly, monthly, custom. Use 'custom' with cron_expr for fine-grained control. |
| labels | array | – | Labels to apply to each instance. |
| max_instances | number | – | Maximum number of instances to create. Default: unlimited. |
| priority | string | – | Priority: urgent, high, medium, low, none. |
| project_id | string | yes | Target project UUID. |
| starts_at | string | – | When to start the schedule (RFC3339). Default: now. |
| timezone | string | – | IANA timezone for schedule evaluation. Default: UTC. |
| title_template | string | yes | Task title template. Supports {{.Date}}, {{.Number}}, {{.Week}}, {{.Month}}. |
No output schema declared.
No examples provided.
create_subtask ~250
Create a subtask under a parent task. Set status_slug for initial status (defaults to the project's default status, NOT the parent's status).
| Name | Type | Req | Description |
|---|---|---|---|
| assignee_id | string | – | Agent or user ID to assign the subtask to. Defaults to the creator if omitted. |
| assignee_type | string | – | Assignee type: agent, user, or unassigned. |
| custom_fields | object | – | Custom field values, keyed by field slug. |
| description | string | – | Subtask description. |
| due_date | string | – | Due date, RFC3339 (e.g. 2026-08-10T12:00:00Z). |
| estimated_hours | number | – | Estimated hours. |
| labels | array | – | Labels for the subtask. |
| parent_task_id | string | yes | Parent task ID. |
| priority | string | – | Priority: urgent, high, medium, low, none. |
| start_after | string | – | Don't surface/feed this subtask before this RFC3339 timestamp. Independent of due_date. |
| status_slug | string | – | Status slug (e.g. 'todo'). Uses project default if omitted. |
| title | string | yes | Subtask title. |
No output schema declared.
No examples provided.
create_task ~254
Create a new task. Check get_my_tasks and list_tasks FIRST to avoid duplicates. Set status_slug for initial status (defaults to project's first status).
| Name | Type | Req | Description |
|---|---|---|---|
| assignee_id | string | – | Assignee ID (user or agent UUID). |
| assignee_type | string | – | Assignee type: user, agent. |
| custom_fields | object | – | Custom field values as key-value pairs. |
| delegation_level | string | – | Delegation level: auto, review, supervised. |
| description | string | – | Task description. |
| due_date | string | – | Due date in RFC3339 format. |
| estimated_hours | number | – | Estimated hours for the task. |
| labels | array | – | Task labels. |
| parent_task_id | string | – | Parent task ID for subtask. |
| priority | string | – | Priority: urgent, high, medium, low, none. |
| project_id | string | yes | Project ID. |
| start_after | string | – | Don't surface/feed this task before this RFC3339 timestamp (e.g. a scheduled retry). Independent of due_date. |
| status_slug | string | – | Status slug (e.g. 'todo'). Uses project default if omitted. |
| title | string | yes | Task title. |
No output schema declared.
No examples provided.
delete_recurring_schedule ~39
Delete a recurring task schedule. Existing task instances are not affected.
| Name | Type | Req | Description |
|---|---|---|---|
| recurring_schedule_id | string | yes | UUID of the recurring schedule to delete. |
No output schema declared.
No examples provided.
export_workspace_config ~26
Export the current workspace configuration as YAML, including rules, project templates, and settings.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
extend_checkout ~116
Push the expiry of an existing checkout_task lock forward, for work that runs longer than the original ttl_minutes. Requires an active checkout in this session (the cached checkout_token from checkout_task) — fails if the lock was never acquired here, already released, or already expired. Server clamps ttl_minutes to [1, 240].
| Name | Type | Req | Description |
|---|---|---|---|
| task_id | string | yes | Task ID whose checkout to extend. |
| ttl_minutes | number | – | New lock TTL in minutes from now (default 120, server clamps to [1, 240]). |
No output schema declared.
No examples provided.
forget ~37
Delete a memory entry. Agents can only delete their own agent-scope memories.
| Name | Type | Req | Description |
|---|---|---|---|
| memory_id | string | yes | UUID of the memory to delete. |
No output schema declared.
No examples provided.
get_artifact ~234
Get artifact details. The bytes are never inlined: download them with the two GETs below. Downloading an artifact is two GETs. Step 1: GET <base>/api/v1/artifacts/<id>/download with header X-Agent-Key: <your agent key> -> 200 JSON {"url": "<presigned URL>"}. Step 2: GET that url with NO headers -> 200, the file bytes. Pitfalls: on step 1 only X-Agent-Key is accepted (X-API-Key and Authorization: Bearer give 401); on step 2 any extra header, Authorization in particular, breaks the presigned signature (400). The artifact's download_path is step 1's path. Never fetch browser_only_url with an agent key: it is a human page and answers 401 by design.
| Name | Type | Req | Description |
|---|---|---|---|
| artifact_id | string | yes | Artifact ID. |
| include_content | boolean | – | Adds download_api_url: step 1 of the download (the API endpoint you call with X-Agent-Key), NOT the file and NOT a link to open. The bytes are never inlined. |
No output schema declared.
No examples provided.
get_assignment_rules ~37
Get effective assignment rules for a project, merged from workspace and project level with source annotations.
| Name | Type | Req | Description |
|---|---|---|---|
| project_id | string | yes | Project ID. |
No output schema declared.
No examples provided.
get_canonical ~145
Query the canonical knowledge layer: returns curated facts, decisions, and strategy docs for a topic, merged from project_memories (key canonical:*) and workspace_memories (kind:canonical). Excludes ephemeral session-checkpoints. Slug aliases are resolved automatically (e.g. mesh-dev == evc-mesh). Call before authoring any doc that might conflict with existing canonical knowledge.
| Name | Type | Req | Description |
|---|---|---|---|
| project | string | – | Optional project slug to narrow results (e.g. 'evc-mesh', 'evc-spark'). Aliases resolved automatically. |
| topic | string | yes | Topic or keyword to search (e.g. 'auth middleware', 'evc-spark roadmap'). |
No output schema declared.
No examples provided.
get_canonical_updates ~137
Fetch canonical decisions broadcast since a given time. Call at ACP step 6 (session start) to catch up on owner directives since your previous session. Returns only privacy:public records targeted at you or all agents.
| Name | Type | Req | Description |
|---|---|---|---|
| agent | string | – | Your agent slug (e.g. 'alice'). Used to filter propagate_to:<slug> records. Omit to get only propagate_to:all records. |
| scope | string | – | Optional project UUID to restrict to project-scoped decisions. |
| since | string | – | RFC3339 cursor. Defaults to your previous session's start time (server-resolved). Omit on first call. |
No output schema declared.
No examples provided.
get_context ~120
Get RECENT ACTIVITY for a project (last 24h by default): event stream with summaries, decisions, errors, plus accumulated project knowledge. Use for ACP Step 4 — what happened recently. For searching specific knowledge, use recall.
| Name | Type | Req | Description |
|---|---|---|---|
| event_types | array | – | Filter by event types. |
| limit | number | – | Max events to return (default 50). |
| project_id | string | yes | Project ID. |
| since | string | – | Only events after this timestamp (RFC3339). |
| tags | array | – | Filter by tags. |
No output schema declared.
No examples provided.
get_doc ~252
Read a document. By DEFAULT returns metadata plus the outline (headings) and NOT the body — a document is far larger than a task, and a body you read stays in your context for the rest of the session. Read the outline first, then pass section="<heading>" for just that part; body=true returns the whole page and should be the exception. The returned version is what update_doc takes as base_version.
| Name | Type | Req | Description |
|---|---|---|---|
| body | boolean | – | Return the full markdown body. Prefer section= when you need one part. |
| doc | string | yes | Document UUID, or a slug path like 'architecture/adr/adr-004' (a path also needs project_id). |
| outline_depth | string | – | Limit the outline to headings at this level or shallower (e.g. '2' for chapters, not every subsection). Default: all levels. |
| project_id | string | – | Project UUID. Required only when doc is a slug path. |
| section | string | – | Return only this section: a heading's text, or its anchor from the outline. |
| version_only | boolean | – | Return just the version — the cheap 'has this changed since I read it?' check before a write. |
No output schema declared.
No examples provided.
get_my_rules ~64
Get ALL governance rules that apply to you: workflow constraints, assignment policies, behavioral requirements. Includes workspace and project-level rules with source annotations. Call at session start (ACP Step 3).
| Name | Type | Req | Description |
|---|---|---|---|
| project_id | string | – | Optional project ID to get project-specific effective rules. |
No output schema declared.
No examples provided.
get_my_tasks ~93
Get YOUR assigned tasks (ACP Step 5). Filter by status_category to focus on active work. Use at session start and after completing tasks to pick up the next assignment.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max results (default 50). |
| project_id | string | – | Filter by project. |
| status_category | string | – | Filter by status category: backlog, todo, in_progress, review, done, cancelled. |
No output schema declared.
No examples provided.
get_project ~27
Get project details with statuses and custom fields.
| Name | Type | Req | Description |
|---|---|---|---|
| project_id | string | yes | Project ID. |
No output schema declared.
No examples provided.
get_project_knowledge ~152
Get ALL PERMANENT KNOWLEDGE for a project: decisions, conventions, accumulated context. Call at session start (ACP Step 2). Returns workspace-level + project-level memories. For RECENT events, use get_context instead.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Max workspace-tier memories (default 100, max 500). |
| min_importance | number | – | Minimum importance_score for workspace-tier (default 0 = all). |
| offset | number | – | Pagination offset for workspace-tier (default 0). |
| project_id | string | yes | Project UUID. |
| tags_any | string | – | Comma-separated tag OR-filter for workspace-tier, e.g. 'kind:decision,kind:incident'. |
No output schema declared.
No examples provided.
get_project_rules ~51
Get all rules configured for a project (all scopes: workspace + project). Kept for backward compatibility — prefer get_my_rules for agent-scoped effective rules.
| Name | Type | Req | Description |
|---|---|---|---|
| project_id | string | yes | Project ID. |
No output schema declared.
No examples provided.
get_recurring_history ~115
Returns the history of all instances for a recurring task schedule. ALWAYS call this when you receive a recurring task — it gives you context on what previous instances accomplished, what issues were found, and what artifacts were produced. Use it to continue work intelligently rather than starting from scratch.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | number | – | Number of most recent instances to return. Default: 5. Use higher value for deep historical context. |
| recurring_schedule_id | string | yes | UUID of the recurring schedule. Available in task.recurring_schedule_id field. |
No output schema declared.
No examples provided.
get_task ~136
Get full task details with optional comments, artifacts, dependencies, and VCS links.
| Name | Type | Req | Description |
|---|---|---|---|
| include_artifacts | boolean | – | Include artifacts. |
| include_comments | boolean | – | Include comments. |
| include_dependencies | boolean | – | Include dependencies. |
| include_vcs_links | boolean | – | Include linked PRs/MRs/commits/branches (id, provider, link_type, external_id, url, status, created_at) — use this instead of a raw REST call to diagnose a misclassified or stuck-status link. |
| task_id | string | yes | Task ID (full UUID or 6–12 char hex short-ID prefix). |
No output schema declared.
No examples provided.
get_task_context ~61
Get EVERYTHING about ONE TASK in a single call: full details + comments + artifacts + dependencies + activity. Use when working on a specific task instead of calling get_task + list_comments + list_artifacts separately.
| Name | Type | Req | Description |
|---|---|---|---|
| task_id | string | yes | Task ID. |
No output schema declared.
No examples provided.
get_team_directory ~24
Get the workspace team directory listing all agents and human members with their profiles.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_workflow_rules ~39
Get workflow rules for a project including allowed transitions, policies, and permissions for the calling agent.
| Name | Type | Req | Description |
|---|---|---|---|
| project_id | string | yes | Project ID. |
No output schema declared.
No examples provided.
heartbeat ~112
Send heartbeat to stay visible. Call at session START with status=online, periodically during work with status=busy. Reports current_task_id, message, and metadata.
| Name | Type | Req | Description |
|---|---|---|---|
| current_task_id | string | – | ID of the task currently being worked on. |
| message | string | – | Short human-readable status message (e.g. 'running tests', 'waiting for review'). |
| metadata | object | – | Arbitrary JSON metadata to store with the heartbeat. |
| status | string | – | Agent status: online, busy, error. |
No output schema declared.
No examples provided.
import_workspace_config ~42
Import workspace configuration from YAML. Applies rules, statuses, and project templates defined in the YAML.
| Name | Type | Req | Description |
|---|---|---|---|
| yaml_content | string | yes | YAML configuration content as a string. |
No output schema declared.
No examples provided.
list_artifacts ~199
List artifacts attached to a task. Each carries download_path; a browser_only_url block, when present, is for a human and must not be fetched. Downloading an artifact is two GETs. Step 1: GET <base>/api/v1/artifacts/<id>/download with header X-Agent-Key: <your agent key> -> 200 JSON {"url": "<presigned URL>"}. Step 2: GET that url with NO headers -> 200, the file bytes. Pitfalls: on step 1 only X-Agent-Key is accepted (X-API-Key and Authorization: Bearer give 401); on step 2 any extra header, Authorization in particular, breaks the presigned signature (400). The artifact's download_path is step 1's path. Never fetch browser_only_url with an agent key: it is a human page and answers 401 by design.
| Name | Type | Req | Description |
|---|---|---|---|
| task_id | string | yes | Task ID. |
No output schema declared.
No examples provided.
list_comments ~115
List comments on a task. Paginated: call again with a higher `page` to read a thread longer than `limit`.
| Name | Type | Req | Description |
|---|---|---|---|
| include_internal | boolean | – | Include internal (agent-only) comments. |
| limit | number | – | Max comments to return (default 50). |
| page | number | – | 1-based page number. Omit for the first page; use with `has_more`/`total_pages` in the response to read the rest of a thread. |
| task_id | string | yes | Task ID. |
No output schema declared.
No examples provided.
list_doc_comments ~149
Read the comments on a document as threads — each top-level comment with its replies nested under it, the quoted passage it is anchored to, and who wrote it. Resolved threads are hidden unless include_resolved=true. A comment whose quoted text no longer exists in the document is marked orphaned=true in its anchor: it is still shown, and it is not pointing anywhere.
| Name | Type | Req | Description |
|---|---|---|---|
| doc | string | yes | Document UUID, or a slug path like 'architecture/adr/adr-004' (a path also needs project_id). |
| include_resolved | boolean | – | Include threads somebody marked resolved. |
| project_id | string | – | Project UUID. Required only when doc is a slug path. |
No output schema declared.
No examples provided.
list_docs ~89
List a project's documents — id, title, slug path, version, who touched them last. Carries NO document bodies, so it is safe to call on a whole project: use it as the map, then get_doc for one page. Returns path and has_children for navigating the tree.
| Name | Type | Req | Description |
|---|---|---|---|
| include_archived | boolean | – | Include archived documents. |
| project_id | string | yes | Project UUID. |
No output schema declared.
No examples provided.
list_projects ~43
List available projects in the workspace.
| Name | Type | Req | Description |
|---|---|---|---|
| include_archived | boolean | – | Include archived projects. |
| workspace_id | string | – | Workspace ID. Defaults to agent's workspace. |
No output schema declared.
No examples provided.
list_recurring_schedules ~42
Lists all recurring task schedules for a project.
| Name | Type | Req | Description |
|---|---|---|---|
| active_only | boolean | – | Only return active schedules. |
| project_id | string | yes | Project ID. |
No output schema declared.
No examples provided.
list_sub_agents ~51
List sub-agents of an agent.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_id | string | – | Parent agent ID. Defaults to the calling agent. |
| recursive | boolean | – | Return all descendants (up to 10 levels deep). |
No output schema declared.
No examples provided.
list_tasks ~537
List tasks with filters. Provide project_id for project-scoped listing or workspace_id for global search across all projects (requires search parameter). Each item's description is included by default and has_description always reflects the task's real content, computed before any trimming below — but on ANY page (plain listing or search=) whose descriptions total more than 200KB, the server blanks descriptions from the TAIL of that page (in item order) to keep the response size bounded, and marks the response truncated:true (field omitted when false). search= usually returns few enough hits to stay under that budget, so it is the practical workaround for a specific known task, but the one guaranteed way to read a given task's full description regardless of any listing's size or order is get_task(task_id).
| Name | Type | Req | Description |
|---|---|---|---|
| assignee_type | string | – | Filter by assignee type: user, agent, unassigned. |
| labels | array | – | Filter by labels. |
| limit | number | – | Max results to return (default 50, max 200). |
| list_revision | number | – | The list_revision echoed back on a previous page of this same project-scoped walk (see the response's list_revision field). Pass it back to continue that walk. If the project's tasks changed since th… |
| order | string | – | Sort direction: asc (default) or desc. Without this, a project larger than `limit` returns its OLDEST tasks, so "what changed recently" walks come back empty and look clean. An invalid value is REFUS… |
| page | number | – | 1-based page number (default 1). The response reports total_pages; without this parameter every page beyond the first was unreachable while the envelope kept advertising them. |
| priority | string | – | Filter by priority: urgent, high, medium, low, none. |
| project_id | string | – | Project ID (required unless workspace_id is provided). |
| search | string | – | Search in title and description. |
| sort | string | – | Sort field: created_at, updated_at, priority, due_date. |
| status_category | string | – | Filter by status category: backlog, todo, in_progress, review, done, cancelled. |
| workspace_id | string | – | Workspace ID for global cross-project search (requires search parameter). |
No output schema declared.
No examples provided.
move_task ~144
Change task status (e.g. todo → in_progress → done). Use status SLUGS (not UUIDs). On move to 'review', task auto-reassigns to creator unless assignee_id is provided.
| Name | Type | Req | Description |
|---|---|---|---|
| assignee_id | string | – | Reassign to this agent/user on move. Overrides auto-reassign to creator on review. |
| assignee_type | string | – | Assignee type if assignee_id is set: user or agent. |
| comment | string | – | Optional comment to add when moving. |
| status_slug | string | yes | Target status slug (e.g. 'in_progress', 'done'). |
| task_id | string | yes | Task ID. |
No output schema declared.
No examples provided.
poll_tasks ~78
Long-poll for new task assignments. Blocks until a task is assigned to this agent or the timeout expires. Returns current assigned tasks and whether any change occurred. Kept for backward compatibility — prefer get_my_tasks for non-blocking access.
| Name | Type | Req | Description |
|---|---|---|---|
| timeout | number | – | Maximum seconds to wait for new assignments (default 30, max 120). |
No output schema declared.
No examples provided.
publish_event ~172
Publish an event to the event bus. For summaries, use event_type='summary'. Add memory={persist:true, key:'decision-name'} to also save as permanent memory. Replaces the deprecated publish_summary tool.
| Name | Type | Req | Description |
|---|---|---|---|
| event_type | string | yes | Event type: summary, status_change, context_update, error, dependency_resolved, custom. |
| memory | object | – | Optional memory hint to persist alongside the event (e.g. key decisions, conventions). |
| payload | object | yes | Event payload as key-value pairs. |
| project_id | string | yes | Project ID. |
| subject | string | yes | Event subject line. |
| tags | array | – | Event tags for filtering. |
| task_id | string | – | Related task ID. |
| ttl_hours | number | – | Time-to-live in hours (default 24). |
No output schema declared.
No examples provided.
publish_summary ~132
Publish a work summary event (convenience wrapper for publish_event with type=summary). Kept for backward compatibility — prefer publish_event with event_type='summary'.
| Name | Type | Req | Description |
|---|---|---|---|
| artifacts_created | array | – | Artifacts created. |
| blockers | array | – | Current blockers. |
| key_decisions | array | – | Key decisions made. |
| metrics | object | – | Metrics (lines changed, tests passed, etc.). |
| next_steps | array | – | Suggested next steps. |
| project_id | string | yes | Project ID. |
| summary | string | yes | Summary of work done. |
| task_id | string | – | Related task ID. |
No output schema declared.
No examples provided.
recall ~497
SEARCH memory by keywords. Use to find a SPECIFIC piece of knowledge, e.g. 'API convention' or 'license decision'. Returns ranked results with scores. For loading ALL project knowledge at session start, use get_project_knowledge instead. Set include_archived=true to retrieve archived memories.
| Name | Type | Req | Description |
|---|---|---|---|
| apply_recency_decay | boolean | – | Sort by relevance * 0.95^days_since_created. |
| created_by | string | – | Filter by agent ID (UUID). |
| include_archived | boolean | – | Include archived memories in results (default false). |
| include_expired | boolean | – | Include expired memories (default false). |
| limit | number | – | Max results (default 10, max 50). This is a hard bound: the response never contains more than limit items. When knowledge-graph boost is enabled, a share of the page (limit/4, at least 1 when limit>=… |
| min_importance | number | – | Minimum importance_score threshold (0-1, default 0.3 — matches the lowest score the server assigns, kind:session-checkpoint, so prior-session hand-offs are returned without an override). Raise it to… |
| offset | number | – | Pagination offset (default 0). |
| order_by | string | – | Sort order: created_at:desc (default), created_at:asc, relevance:desc, decayed_relevance:desc. |
| project_id | string | – | Filter to a specific project. |
| query | string | yes | Full-text search query. |
| relevance_min | number | – | Minimum relevance score (0-1). |
| scope | string | – | Filter by scope: workspace, project, agent, or all (default). |
| since | string | – | Return memories created at or after this RFC3339 timestamp. |
| tags | array | – | AND-filter: memory must contain ALL listed tags. |
| tags_any | array | – | OR-filter: memory must contain AT LEAST ONE of these tags. |
| until | string | – | Return memories created at or before this RFC3339 timestamp. |
No output schema declared.
No examples provided.
recall_with_graph ~149
Search memory with Knowledge Graph expansion. Seeds from hybrid recall, then BFS-traverses memory_edges up to hops depth. Returns memories ranked by composite score with hop_distance and provenance fields. Use when you want broader context — related decisions, connected incidents, derived learnings.
| Name | Type | Req | Description |
|---|---|---|---|
| hops | number | – | Graph traversal depth (default 2, max 5). |
| project_id | string | – | Filter to a specific project. |
| q | string | yes | Search query (keywords or natural language). |
| task_id | string | – | Optional task ID — used as cache key discriminator for session-scoped traversal. |
| weight_threshold | number | – | Minimum edge weight to follow (default 0.3). |
No output schema declared.
No examples provided.
record_owner_decision ~311
Record a directive from the workspace owner as a canonical decision in project_knowledge. Broadcasts to specified agents via propagate_to tags. privacy:private records are stored but EXCLUDED from get_canonical_updates. Auto-flags private if text contains secrets. If task_id is given, also records this as a human_gate decision on that task (docs/human-gate-decision-recorded.md in evc-mesh) — releases the gate as a consequence if it's currently live, and links back via canonical_key. Best-effort: a failure here is reported in the result but does not undo the canonical write.
| Name | Type | Req | Description |
|---|---|---|---|
| privacy | string | – | 'public' (default, visible in change-feed) or 'private' (recorded but hidden). |
| propagate_to | array | – | Agent slugs to propagate to, e.g. ['alice','bob']. Use ['all'] for workspace-wide broadcast. |
| scope | string | – | Optional project_id UUID. Omit for workspace-level decisions. |
| summary | string | yes | One-line summary used as UPSERT key (dedupes same decision on same day). |
| task_id | string | – | Optional task UUID this decision answers. When set, also records a human_gate decision on that task (provenance=attested, channel=telegram, quote=text) — releasing a live human_gate as a consequence.… |
| text | string | yes | Full text of the decision/directive. |
No output schema declared.
No examples provided.
register_sub_agent ~66
Register a sub-agent under the calling agent.
| Name | Type | Req | Description |
|---|---|---|---|
| agent_type | string | yes | Agent type: claude_code, openclaw, cline, aider, custom. |
| capabilities | object | – | Agent capabilities as key-value pairs. |
| name | string | yes | Sub-agent name. |
No output schema declared.
No examples provided.
release_task ~57
Release the exclusive lock on a task acquired via checkout_task. Call when done with the task or if you need to hand it off. The lock is also released automatically when it expires.
| Name | Type | Req | Description |
|---|---|---|---|
| task_id | string | yes | Task ID to release. |
No output schema declared.
No examples provided.
What is the io.github.entire-vc/evc-mesh-mcp server?
io.github.entire-vc/evc-mesh-mcp is listed in the public MCP registry as io.github.entire-vc/evc-mesh-mcp. Tasks, comments, shared memory and handoffs for teams of people and AI agents, over MCP. This page covers its container image (ghcr.io/entire-vc/evc-mesh-mcp:0.1.5).
Is the io.github.entire-vc/evc-mesh-mcp server safe to use?
io.github.entire-vc/evc-mesh-mcp scores 44 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.entire-vc/evc-mesh-mcp server expose?
io.github.entire-vc/evc-mesh-mcp exposes 63 tools: add_comment, add_dependency, add_vcs_link, assign_task, checkout_task, and 58 more. Their descriptions and schemas cost roughly 11,163 tokens of context every time the server is loaded.
Is the io.github.entire-vc/evc-mesh-mcp server still maintained?
io.github.entire-vc/evc-mesh-mcp is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.entire-vc/evc-mesh-mcp server under?
io.github.entire-vc/evc-mesh-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.