Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

io.github.entire-vc/evc-mesh-mcp

OCI · GHCR.IO/ENTIRE-VC/EVC-MESH-MCP:0.1.5 · 4 COMPONENTS · SCANNED OCT 2

Tasks, comments, shared memory and handoffs for teams of people and AI agents, over MCP.

+4 this week 44 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security0
  • No malware scan is available for this kind of package: the supply-chain vendors we use do not cover it. This is a permanent gap in our coverage, not a finding about the package.Unverified
  • Known CVEs could not be checked: this artifact ships no SBOM or dependency manifest, so there is no dependency list to read.Unverified
  • Install-script risk not yet assessed.Unverified
  • Dependency health could not be checked: this artifact ships no SBOM or dependency manifest, so there is no dependency list to read.Unverified
Provenance & Transparency45
Schema Quality & AI Usability72
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 11163 tokens (~177/item across 63 items; 63 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
  • Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 5 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 63 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

How do I install the io.github.entire-vc/evc-mesh-mcp server?

io.github.entire-vc/evc-mesh-mcp runs locally as a container image, launched with docker run --rm -i -e MESH_API_URL -e MESH_AGENT_KEY -e MESH_MCP_PROFILE ghcr.io/entire-vc/evc-mesh-mcp:0.1.5. Ready-made configuration for Claude, Cursor, VS Code, Codex and 3 more is on this page, copied from each client's own documentation.

oci · ghcr.io/entire-vc/evc-mesh-mcp:0.1.5

# add to Claude Code
claude mcp add entire-vc-evc-mesh-mcp -- docker run --rm -i -e MESH_API_URL -e MESH_AGENT_KEY -e MESH_MCP_PROFILE ghcr.io/entire-vc/evc-mesh-mcp:0.1.5

This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.

// .cursor/mcp.json
{
  "mcpServers": {
    "entire-vc-evc-mesh-mcp": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "-e",
        "MESH_API_URL",
        "-e",
        "MESH_AGENT_KEY",
        "-e",
        "MESH_MCP_PROFILE",
        "ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
      ]
    }
  }
}

This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.

// .vscode/mcp.json
{
  "servers": {
    "entire-vc-evc-mesh-mcp": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "-e",
        "MESH_API_URL",
        "-e",
        "MESH_AGENT_KEY",
        "-e",
        "MESH_MCP_PROFILE",
        "ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
      ]
    }
  }
}

This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.

# add to Codex CLI
codex mcp add entire-vc-evc-mesh-mcp -- docker run --rm -i -e MESH_API_URL -e MESH_AGENT_KEY -e MESH_MCP_PROFILE ghcr.io/entire-vc/evc-mesh-mcp:0.1.5

This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.

// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "entire-vc-evc-mesh-mcp": {
      "type": "local",
      "command": [
        "docker",
        "run",
        "--rm",
        "-i",
        "-e",
        "MESH_API_URL",
        "-e",
        "MESH_AGENT_KEY",
        "-e",
        "MESH_MCP_PROFILE",
        "ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
      ],
      "enabled": true
    }
  }
}

This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.

# ~/.hermes/config.yaml
mcp_servers:
  entire-vc-evc-mesh-mcp:
    command: "docker"
    args: ["run", "--rm", "-i", "-e", "MESH_API_URL", "-e", "MESH_AGENT_KEY", "-e", "MESH_MCP_PROFILE", "ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"]

This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.

// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "entire-vc-evc-mesh-mcp": {
      "Transport": "stdio",
      "Command": "docker",
      "Arguments": [
        "run",
        "--rm",
        "-i",
        "-e",
        "MESH_API_URL",
        "-e",
        "MESH_AGENT_KEY",
        "-e",
        "MESH_MCP_PROFILE",
        "ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
      ]
    }
  }
}

This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.

// mcp.json
{
  "mcpServers": {
    "entire-vc-evc-mesh-mcp": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-i",
        "-e",
        "MESH_API_URL",
        "-e",
        "MESH_AGENT_KEY",
        "-e",
        "MESH_MCP_PROFILE",
        "ghcr.io/entire-vc/evc-mesh-mcp:0.1.5"
      ]
    }
  }
}

This image reads MESH_API_URL, MESH_AGENT_KEY and MESH_MCP_PROFILE. Set them in your client's env block for this server; docker run -e passes each one through to the container.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 2 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.

  • 30 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.

  • 28 Sept 26 +1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 26 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.

  • 25 Sept 26 0
    • Stability: unverified → 0.03 ▲ functional
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 24 Sept 26 40

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 2 Oct 2026 · Analysed oci/ghcr.io/entire-vc/evc-mesh-mcp:0.1.5

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem oci
Reason No attestation published

Background: How many MCP packages publish verified provenance →

MCP tools · 63 exposed · ~11,163 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
add_comment ~305

Add a comment to a task. If the body @-mentions someone, the response carries a `delivery` array — one entry per mentioned handle — reporting whether it actually reached a path they consume (their task queue, a notification) or was skipped/failed and why; a `hint` field suggests the fix when there is one (e.g. assign the task). Omitted entirely when the comment mentions nobody.

NameTypeReqDescription
bodystringyesComment body (markdown supported).
is_internalboolean–Mark as internal (agent-only visible).
metadataobject–Additional metadata as key-value pairs. Set {"informational": true} on a comment you write on a task that is ALREADY done/cancelled when your comment needs no action from its assignee — a plain ackno…
parent_comment_idstring–Parent comment ID for threading.
task_idstringyesTask ID.

No output schema declared.

No examples provided.

add_dependency ~61

Add a dependency between two tasks.

NameTypeReqDescription
dependency_typestring–Dependency type: blocks, relates_to, is_child_of.
depends_on_task_idstringyesID of the task this depends on.
task_idstringyesTask ID.

No output schema declared.

No examples provided.

add_vcs_link ~439

Link a task to a pull request, commit, or branch. This is what makes the task↔PR join real: a task with no VCS link cannot be matched to the code that implements it, so PR-driven status automation and any 'what shipped for this task?' report simply will not see it. Call it as soon as the PR exists. Only task_id and url are needed — provider, link_type and external_id are inferred from a GitHub or GitLab URL. If the PR is ALREADY merged (or closed) by the time you call this — e.g. you finished, merged, and are linking retroactively — pass status='merged' (or 'closed'). Without it the link starts as 'open' and the done-evidence gate will block move→done on it forever: no GitHub webhook fires for a merge that happened before the link existed.

NameTypeReqDescription
external_idstring–PR number, commit SHA, or branch name. Inferred from the URL; only needed when the URL is not a recognised PR/commit/branch link.
link_typestring–What the URL points at: pr (alias: pull_request), commit, branch. Inferred from the URL path; defaults to pr.
providerstring–VCS provider: github, gitlab. Inferred from the URL host; defaults to github.
statusstring–PR status, if you already know it: open, merged, closed. Pass 'merged' when linking a PR that was merged before this call — that is the one case a webhook can never backfill. Omit it to let the link…
task_idstringyesTask ID.
titlestring–Human-readable label, e.g. the PR title.
urlstringyesLink URL, e.g. https://github.com/owner/repo/pull/123.

No output schema declared.

No examples provided.

assign_task ~75

Assign a task to a user or agent.

NameTypeReqDescription
assign_to_selfboolean–Assign to the calling agent.
assignee_idstring–Assignee UUID. Omit to unassign.
assignee_typestring–Assignee type: user, agent.
task_idstringyesTask ID.

No output schema declared.

No examples provided.

checkout_task ~88

Atomically acquire an exclusive lock on a task. Prevents other agents from checking out the same task simultaneously. The lock is TTL-based and will expire automatically after ttl_minutes (default 120). Use before starting work on a task to ensure exclusive access.

NameTypeReqDescription
task_idstringyesTask ID to check out.
ttl_minutesnumber–Lock TTL in minutes (default 120).

No output schema declared.

No examples provided.

clear_human_gate ~185

Release a human gate. Read human_gate_info on get_task first and go by clear_path. clear_path="clear_endpoint" means YOU armed this gate through set_human_gate and it carries no marker comment — this tool releases it, and a withdrawal comment would be a silent no-op. clear_path="withdraw_marker" means the ask lives in a "Blocking @" comment: this tool refuses, and you take it down by posting a short negator comment instead. Everything else is user-only — a gate a human armed, or one raw-armed via PATCH/UI with no author — and an agent key gets a 403 naming the exit it CAN reach: record the human's answer via a human-gate decision. Re-read human_gate after any release; a posted comment is not a cleared gate.

NameTypeReqDescription
task_idstringyesTask ID whose gate to clear.

No output schema declared.

No examples provided.

comment_doc ~264

Comment on a document. To comment on a specific passage, pass quote with the text exactly as the document reads it — the server finds it and anchors the comment there, so you never compute a position yourself (there is no offset parameter, and a position you calculated would silently point at the wrong sentence). Without quote the comment is on the whole document. Your comment appears in the same thread humans see in the document UI.

NameTypeReqDescription
bodystringyesThe comment text. Markdown; @slug mentions notify that person or agent.
docstringyesDocument UUID, or a slug path like 'architecture/adr/adr-004' (a path also needs project_id).
project_idstring–Project UUID. Required only when doc is a slug path.
quotestring–The passage being commented on, copied from the document exactly. One sentence is plenty. Omit to comment on the document as a whole.
quote_contextstring–A longer passage containing the quote exactly once — send this when the quote occurs several times in the document and you were told it was ambiguous.
reply_tostring–UUID of the comment being answered. A reply inherits that thread's anchor, so it takes no quote of its own.

No output schema declared.

No examples provided.

create_doc ~127

Create a document in a project. Returns its metadata and version — the version is what update_doc takes as base_version, so a create followed by an edit needs no read in between. The body you sent is not echoed back.

NameTypeReqDescription
bodystring–Markdown body.
parent_idstring–Parent document UUID, to nest this one under it.
positionnumber–Sort position among siblings.
project_idstringyesProject UUID.
slugstring–URL slug. Derived from the title if omitted.
titlestringyesDocument title.

No output schema declared.

No examples provided.

create_recurring_task ~329

Creates a recurring task schedule that automatically spawns task instances on a schedule. Each instance gets access to the previous instance's summary. Use this for regular automated work: weekly reports, daily checks, periodic audits.

NameTypeReqDescription
assignee_idstring–Agent or user UUID to assign each instance.
assignee_typestring–Assignee type: user, agent, unassigned.
cron_exprstring–5-field cron expression (required if frequency=custom). Example: '0 9 * * 1' = every Monday at 9am.
description_templatestring–Task description template. Also supports {{.PrevSummary}} for previous instance context.
ends_atstring–When to stop the schedule (RFC3339). Default: no end.
frequencystringyesRecurrence frequency: daily, weekly, monthly, custom. Use 'custom' with cron_expr for fine-grained control.
labelsarray–Labels to apply to each instance.
max_instancesnumber–Maximum number of instances to create. Default: unlimited.
prioritystring–Priority: urgent, high, medium, low, none.
project_idstringyesTarget project UUID.
starts_atstring–When to start the schedule (RFC3339). Default: now.
timezonestring–IANA timezone for schedule evaluation. Default: UTC.
title_templatestringyesTask title template. Supports {{.Date}}, {{.Number}}, {{.Week}}, {{.Month}}.

No output schema declared.

No examples provided.

create_subtask ~250

Create a subtask under a parent task. Set status_slug for initial status (defaults to the project's default status, NOT the parent's status).

NameTypeReqDescription
assignee_idstring–Agent or user ID to assign the subtask to. Defaults to the creator if omitted.
assignee_typestring–Assignee type: agent, user, or unassigned.
custom_fieldsobject–Custom field values, keyed by field slug.
descriptionstring–Subtask description.
due_datestring–Due date, RFC3339 (e.g. 2026-08-10T12:00:00Z).
estimated_hoursnumber–Estimated hours.
labelsarray–Labels for the subtask.
parent_task_idstringyesParent task ID.
prioritystring–Priority: urgent, high, medium, low, none.
start_afterstring–Don't surface/feed this subtask before this RFC3339 timestamp. Independent of due_date.
status_slugstring–Status slug (e.g. 'todo'). Uses project default if omitted.
titlestringyesSubtask title.

No output schema declared.

No examples provided.

create_task ~254

Create a new task. Check get_my_tasks and list_tasks FIRST to avoid duplicates. Set status_slug for initial status (defaults to project's first status).

NameTypeReqDescription
assignee_idstring–Assignee ID (user or agent UUID).
assignee_typestring–Assignee type: user, agent.
custom_fieldsobject–Custom field values as key-value pairs.
delegation_levelstring–Delegation level: auto, review, supervised.
descriptionstring–Task description.
due_datestring–Due date in RFC3339 format.
estimated_hoursnumber–Estimated hours for the task.
labelsarray–Task labels.
parent_task_idstring–Parent task ID for subtask.
prioritystring–Priority: urgent, high, medium, low, none.
project_idstringyesProject ID.
start_afterstring–Don't surface/feed this task before this RFC3339 timestamp (e.g. a scheduled retry). Independent of due_date.
status_slugstring–Status slug (e.g. 'todo'). Uses project default if omitted.
titlestringyesTask title.

No output schema declared.

No examples provided.

delete_recurring_schedule ~39

Delete a recurring task schedule. Existing task instances are not affected.

NameTypeReqDescription
recurring_schedule_idstringyesUUID of the recurring schedule to delete.

No output schema declared.

No examples provided.

export_workspace_config ~26

Export the current workspace configuration as YAML, including rules, project templates, and settings.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

extend_checkout ~116

Push the expiry of an existing checkout_task lock forward, for work that runs longer than the original ttl_minutes. Requires an active checkout in this session (the cached checkout_token from checkout_task) — fails if the lock was never acquired here, already released, or already expired. Server clamps ttl_minutes to [1, 240].

NameTypeReqDescription
task_idstringyesTask ID whose checkout to extend.
ttl_minutesnumber–New lock TTL in minutes from now (default 120, server clamps to [1, 240]).

No output schema declared.

No examples provided.

forget ~37

Delete a memory entry. Agents can only delete their own agent-scope memories.

NameTypeReqDescription
memory_idstringyesUUID of the memory to delete.

No output schema declared.

No examples provided.

get_artifact ~234

Get artifact details. The bytes are never inlined: download them with the two GETs below. Downloading an artifact is two GETs. Step 1: GET <base>/api/v1/artifacts/<id>/download with header X-Agent-Key: <your agent key> -> 200 JSON {"url": "<presigned URL>"}. Step 2: GET that url with NO headers -> 200, the file bytes. Pitfalls: on step 1 only X-Agent-Key is accepted (X-API-Key and Authorization: Bearer give 401); on step 2 any extra header, Authorization in particular, breaks the presigned signature (400). The artifact's download_path is step 1's path. Never fetch browser_only_url with an agent key: it is a human page and answers 401 by design.

NameTypeReqDescription
artifact_idstringyesArtifact ID.
include_contentboolean–Adds download_api_url: step 1 of the download (the API endpoint you call with X-Agent-Key), NOT the file and NOT a link to open. The bytes are never inlined.

No output schema declared.

No examples provided.

get_assignment_rules ~37

Get effective assignment rules for a project, merged from workspace and project level with source annotations.

NameTypeReqDescription
project_idstringyesProject ID.

No output schema declared.

No examples provided.

get_canonical ~145

Query the canonical knowledge layer: returns curated facts, decisions, and strategy docs for a topic, merged from project_memories (key canonical:*) and workspace_memories (kind:canonical). Excludes ephemeral session-checkpoints. Slug aliases are resolved automatically (e.g. mesh-dev == evc-mesh). Call before authoring any doc that might conflict with existing canonical knowledge.

NameTypeReqDescription
projectstring–Optional project slug to narrow results (e.g. 'evc-mesh', 'evc-spark'). Aliases resolved automatically.
topicstringyesTopic or keyword to search (e.g. 'auth middleware', 'evc-spark roadmap').

No output schema declared.

No examples provided.

get_canonical_updates ~137

Fetch canonical decisions broadcast since a given time. Call at ACP step 6 (session start) to catch up on owner directives since your previous session. Returns only privacy:public records targeted at you or all agents.

NameTypeReqDescription
agentstring–Your agent slug (e.g. 'alice'). Used to filter propagate_to:<slug> records. Omit to get only propagate_to:all records.
scopestring–Optional project UUID to restrict to project-scoped decisions.
sincestring–RFC3339 cursor. Defaults to your previous session's start time (server-resolved). Omit on first call.

No output schema declared.

No examples provided.

get_context ~120

Get RECENT ACTIVITY for a project (last 24h by default): event stream with summaries, decisions, errors, plus accumulated project knowledge. Use for ACP Step 4 — what happened recently. For searching specific knowledge, use recall.

NameTypeReqDescription
event_typesarray–Filter by event types.
limitnumber–Max events to return (default 50).
project_idstringyesProject ID.
sincestring–Only events after this timestamp (RFC3339).
tagsarray–Filter by tags.

No output schema declared.

No examples provided.

get_doc ~252

Read a document. By DEFAULT returns metadata plus the outline (headings) and NOT the body — a document is far larger than a task, and a body you read stays in your context for the rest of the session. Read the outline first, then pass section="<heading>" for just that part; body=true returns the whole page and should be the exception. The returned version is what update_doc takes as base_version.

NameTypeReqDescription
bodyboolean–Return the full markdown body. Prefer section= when you need one part.
docstringyesDocument UUID, or a slug path like 'architecture/adr/adr-004' (a path also needs project_id).
outline_depthstring–Limit the outline to headings at this level or shallower (e.g. '2' for chapters, not every subsection). Default: all levels.
project_idstring–Project UUID. Required only when doc is a slug path.
sectionstring–Return only this section: a heading's text, or its anchor from the outline.
version_onlyboolean–Return just the version — the cheap 'has this changed since I read it?' check before a write.

No output schema declared.

No examples provided.

get_my_rules ~64

Get ALL governance rules that apply to you: workflow constraints, assignment policies, behavioral requirements. Includes workspace and project-level rules with source annotations. Call at session start (ACP Step 3).

NameTypeReqDescription
project_idstring–Optional project ID to get project-specific effective rules.

No output schema declared.

No examples provided.

get_my_tasks ~93

Get YOUR assigned tasks (ACP Step 5). Filter by status_category to focus on active work. Use at session start and after completing tasks to pick up the next assignment.

NameTypeReqDescription
limitnumber–Max results (default 50).
project_idstring–Filter by project.
status_categorystring–Filter by status category: backlog, todo, in_progress, review, done, cancelled.

No output schema declared.

No examples provided.

get_project ~27

Get project details with statuses and custom fields.

NameTypeReqDescription
project_idstringyesProject ID.

No output schema declared.

No examples provided.

get_project_knowledge ~152

Get ALL PERMANENT KNOWLEDGE for a project: decisions, conventions, accumulated context. Call at session start (ACP Step 2). Returns workspace-level + project-level memories. For RECENT events, use get_context instead.

NameTypeReqDescription
limitnumber–Max workspace-tier memories (default 100, max 500).
min_importancenumber–Minimum importance_score for workspace-tier (default 0 = all).
offsetnumber–Pagination offset for workspace-tier (default 0).
project_idstringyesProject UUID.
tags_anystring–Comma-separated tag OR-filter for workspace-tier, e.g. 'kind:decision,kind:incident'.

No output schema declared.

No examples provided.

get_project_rules ~51

Get all rules configured for a project (all scopes: workspace + project). Kept for backward compatibility — prefer get_my_rules for agent-scoped effective rules.

NameTypeReqDescription
project_idstringyesProject ID.

No output schema declared.

No examples provided.

get_recurring_history ~115

Returns the history of all instances for a recurring task schedule. ALWAYS call this when you receive a recurring task — it gives you context on what previous instances accomplished, what issues were found, and what artifacts were produced. Use it to continue work intelligently rather than starting from scratch.

NameTypeReqDescription
limitnumber–Number of most recent instances to return. Default: 5. Use higher value for deep historical context.
recurring_schedule_idstringyesUUID of the recurring schedule. Available in task.recurring_schedule_id field.

No output schema declared.

No examples provided.

get_task ~136

Get full task details with optional comments, artifacts, dependencies, and VCS links.

NameTypeReqDescription
include_artifactsboolean–Include artifacts.
include_commentsboolean–Include comments.
include_dependenciesboolean–Include dependencies.
include_vcs_linksboolean–Include linked PRs/MRs/commits/branches (id, provider, link_type, external_id, url, status, created_at) — use this instead of a raw REST call to diagnose a misclassified or stuck-status link.
task_idstringyesTask ID (full UUID or 6–12 char hex short-ID prefix).

No output schema declared.

No examples provided.

get_task_context ~61

Get EVERYTHING about ONE TASK in a single call: full details + comments + artifacts + dependencies + activity. Use when working on a specific task instead of calling get_task + list_comments + list_artifacts separately.

NameTypeReqDescription
task_idstringyesTask ID.

No output schema declared.

No examples provided.

get_team_directory ~24

Get the workspace team directory listing all agents and human members with their profiles.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_workflow_rules ~39

Get workflow rules for a project including allowed transitions, policies, and permissions for the calling agent.

NameTypeReqDescription
project_idstringyesProject ID.

No output schema declared.

No examples provided.

heartbeat ~112

Send heartbeat to stay visible. Call at session START with status=online, periodically during work with status=busy. Reports current_task_id, message, and metadata.

NameTypeReqDescription
current_task_idstring–ID of the task currently being worked on.
messagestring–Short human-readable status message (e.g. 'running tests', 'waiting for review').
metadataobject–Arbitrary JSON metadata to store with the heartbeat.
statusstring–Agent status: online, busy, error.

No output schema declared.

No examples provided.

import_workspace_config ~42

Import workspace configuration from YAML. Applies rules, statuses, and project templates defined in the YAML.

NameTypeReqDescription
yaml_contentstringyesYAML configuration content as a string.

No output schema declared.

No examples provided.

list_artifacts ~199

List artifacts attached to a task. Each carries download_path; a browser_only_url block, when present, is for a human and must not be fetched. Downloading an artifact is two GETs. Step 1: GET <base>/api/v1/artifacts/<id>/download with header X-Agent-Key: <your agent key> -> 200 JSON {"url": "<presigned URL>"}. Step 2: GET that url with NO headers -> 200, the file bytes. Pitfalls: on step 1 only X-Agent-Key is accepted (X-API-Key and Authorization: Bearer give 401); on step 2 any extra header, Authorization in particular, breaks the presigned signature (400). The artifact's download_path is step 1's path. Never fetch browser_only_url with an agent key: it is a human page and answers 401 by design.

NameTypeReqDescription
task_idstringyesTask ID.

No output schema declared.

No examples provided.

list_comments ~115

List comments on a task. Paginated: call again with a higher `page` to read a thread longer than `limit`.

NameTypeReqDescription
include_internalboolean–Include internal (agent-only) comments.
limitnumber–Max comments to return (default 50).
pagenumber–1-based page number. Omit for the first page; use with `has_more`/`total_pages` in the response to read the rest of a thread.
task_idstringyesTask ID.

No output schema declared.

No examples provided.

list_doc_comments ~149

Read the comments on a document as threads — each top-level comment with its replies nested under it, the quoted passage it is anchored to, and who wrote it. Resolved threads are hidden unless include_resolved=true. A comment whose quoted text no longer exists in the document is marked orphaned=true in its anchor: it is still shown, and it is not pointing anywhere.

NameTypeReqDescription
docstringyesDocument UUID, or a slug path like 'architecture/adr/adr-004' (a path also needs project_id).
include_resolvedboolean–Include threads somebody marked resolved.
project_idstring–Project UUID. Required only when doc is a slug path.

No output schema declared.

No examples provided.

list_docs ~89

List a project's documents — id, title, slug path, version, who touched them last. Carries NO document bodies, so it is safe to call on a whole project: use it as the map, then get_doc for one page. Returns path and has_children for navigating the tree.

NameTypeReqDescription
include_archivedboolean–Include archived documents.
project_idstringyesProject UUID.

No output schema declared.

No examples provided.

list_projects ~43

List available projects in the workspace.

NameTypeReqDescription
include_archivedboolean–Include archived projects.
workspace_idstring–Workspace ID. Defaults to agent's workspace.

No output schema declared.

No examples provided.

list_recurring_schedules ~42

Lists all recurring task schedules for a project.

NameTypeReqDescription
active_onlyboolean–Only return active schedules.
project_idstringyesProject ID.

No output schema declared.

No examples provided.

list_sub_agents ~51

List sub-agents of an agent.

NameTypeReqDescription
agent_idstring–Parent agent ID. Defaults to the calling agent.
recursiveboolean–Return all descendants (up to 10 levels deep).

No output schema declared.

No examples provided.

list_tasks ~537

List tasks with filters. Provide project_id for project-scoped listing or workspace_id for global search across all projects (requires search parameter). Each item's description is included by default and has_description always reflects the task's real content, computed before any trimming below — but on ANY page (plain listing or search=) whose descriptions total more than 200KB, the server blanks descriptions from the TAIL of that page (in item order) to keep the response size bounded, and marks the response truncated:true (field omitted when false). search= usually returns few enough hits to stay under that budget, so it is the practical workaround for a specific known task, but the one guaranteed way to read a given task's full description regardless of any listing's size or order is get_task(task_id).

NameTypeReqDescription
assignee_typestring–Filter by assignee type: user, agent, unassigned.
labelsarray–Filter by labels.
limitnumber–Max results to return (default 50, max 200).
list_revisionnumber–The list_revision echoed back on a previous page of this same project-scoped walk (see the response's list_revision field). Pass it back to continue that walk. If the project's tasks changed since th…
orderstring–Sort direction: asc (default) or desc. Without this, a project larger than `limit` returns its OLDEST tasks, so "what changed recently" walks come back empty and look clean. An invalid value is REFUS…
pagenumber–1-based page number (default 1). The response reports total_pages; without this parameter every page beyond the first was unreachable while the envelope kept advertising them.
prioritystring–Filter by priority: urgent, high, medium, low, none.
project_idstring–Project ID (required unless workspace_id is provided).
searchstring–Search in title and description.
sortstring–Sort field: created_at, updated_at, priority, due_date.
status_categorystring–Filter by status category: backlog, todo, in_progress, review, done, cancelled.
workspace_idstring–Workspace ID for global cross-project search (requires search parameter).

No output schema declared.

No examples provided.

move_task ~144

Change task status (e.g. todo → in_progress → done). Use status SLUGS (not UUIDs). On move to 'review', task auto-reassigns to creator unless assignee_id is provided.

NameTypeReqDescription
assignee_idstring–Reassign to this agent/user on move. Overrides auto-reassign to creator on review.
assignee_typestring–Assignee type if assignee_id is set: user or agent.
commentstring–Optional comment to add when moving.
status_slugstringyesTarget status slug (e.g. 'in_progress', 'done').
task_idstringyesTask ID.

No output schema declared.

No examples provided.

poll_tasks ~78

Long-poll for new task assignments. Blocks until a task is assigned to this agent or the timeout expires. Returns current assigned tasks and whether any change occurred. Kept for backward compatibility — prefer get_my_tasks for non-blocking access.

NameTypeReqDescription
timeoutnumber–Maximum seconds to wait for new assignments (default 30, max 120).

No output schema declared.

No examples provided.

publish_event ~172

Publish an event to the event bus. For summaries, use event_type='summary'. Add memory={persist:true, key:'decision-name'} to also save as permanent memory. Replaces the deprecated publish_summary tool.

NameTypeReqDescription
event_typestringyesEvent type: summary, status_change, context_update, error, dependency_resolved, custom.
memoryobject–Optional memory hint to persist alongside the event (e.g. key decisions, conventions).
payloadobjectyesEvent payload as key-value pairs.
project_idstringyesProject ID.
subjectstringyesEvent subject line.
tagsarray–Event tags for filtering.
task_idstring–Related task ID.
ttl_hoursnumber–Time-to-live in hours (default 24).

No output schema declared.

No examples provided.

publish_summary ~132

Publish a work summary event (convenience wrapper for publish_event with type=summary). Kept for backward compatibility — prefer publish_event with event_type='summary'.

NameTypeReqDescription
artifacts_createdarray–Artifacts created.
blockersarray–Current blockers.
key_decisionsarray–Key decisions made.
metricsobject–Metrics (lines changed, tests passed, etc.).
next_stepsarray–Suggested next steps.
project_idstringyesProject ID.
summarystringyesSummary of work done.
task_idstring–Related task ID.

No output schema declared.

No examples provided.

recall ~497

SEARCH memory by keywords. Use to find a SPECIFIC piece of knowledge, e.g. 'API convention' or 'license decision'. Returns ranked results with scores. For loading ALL project knowledge at session start, use get_project_knowledge instead. Set include_archived=true to retrieve archived memories.

NameTypeReqDescription
apply_recency_decayboolean–Sort by relevance * 0.95^days_since_created.
created_bystring–Filter by agent ID (UUID).
include_archivedboolean–Include archived memories in results (default false).
include_expiredboolean–Include expired memories (default false).
limitnumber–Max results (default 10, max 50). This is a hard bound: the response never contains more than limit items. When knowledge-graph boost is enabled, a share of the page (limit/4, at least 1 when limit>=…
min_importancenumber–Minimum importance_score threshold (0-1, default 0.3 — matches the lowest score the server assigns, kind:session-checkpoint, so prior-session hand-offs are returned without an override). Raise it to…
offsetnumber–Pagination offset (default 0).
order_bystring–Sort order: created_at:desc (default), created_at:asc, relevance:desc, decayed_relevance:desc.
project_idstring–Filter to a specific project.
querystringyesFull-text search query.
relevance_minnumber–Minimum relevance score (0-1).
scopestring–Filter by scope: workspace, project, agent, or all (default).
sincestring–Return memories created at or after this RFC3339 timestamp.
tagsarray–AND-filter: memory must contain ALL listed tags.
tags_anyarray–OR-filter: memory must contain AT LEAST ONE of these tags.
untilstring–Return memories created at or before this RFC3339 timestamp.

No output schema declared.

No examples provided.

recall_with_graph ~149

Search memory with Knowledge Graph expansion. Seeds from hybrid recall, then BFS-traverses memory_edges up to hops depth. Returns memories ranked by composite score with hop_distance and provenance fields. Use when you want broader context — related decisions, connected incidents, derived learnings.

NameTypeReqDescription
hopsnumber–Graph traversal depth (default 2, max 5).
project_idstring–Filter to a specific project.
qstringyesSearch query (keywords or natural language).
task_idstring–Optional task ID — used as cache key discriminator for session-scoped traversal.
weight_thresholdnumber–Minimum edge weight to follow (default 0.3).

No output schema declared.

No examples provided.

record_owner_decision ~311

Record a directive from the workspace owner as a canonical decision in project_knowledge. Broadcasts to specified agents via propagate_to tags. privacy:private records are stored but EXCLUDED from get_canonical_updates. Auto-flags private if text contains secrets. If task_id is given, also records this as a human_gate decision on that task (docs/human-gate-decision-recorded.md in evc-mesh) — releases the gate as a consequence if it's currently live, and links back via canonical_key. Best-effort: a failure here is reported in the result but does not undo the canonical write.

NameTypeReqDescription
privacystring–'public' (default, visible in change-feed) or 'private' (recorded but hidden).
propagate_toarray–Agent slugs to propagate to, e.g. ['alice','bob']. Use ['all'] for workspace-wide broadcast.
scopestring–Optional project_id UUID. Omit for workspace-level decisions.
summarystringyesOne-line summary used as UPSERT key (dedupes same decision on same day).
task_idstring–Optional task UUID this decision answers. When set, also records a human_gate decision on that task (provenance=attested, channel=telegram, quote=text) — releasing a live human_gate as a consequence.…
textstringyesFull text of the decision/directive.

No output schema declared.

No examples provided.

register_sub_agent ~66

Register a sub-agent under the calling agent.

NameTypeReqDescription
agent_typestringyesAgent type: claude_code, openclaw, cline, aider, custom.
capabilitiesobject–Agent capabilities as key-value pairs.
namestringyesSub-agent name.

No output schema declared.

No examples provided.

release_task ~57

Release the exclusive lock on a task acquired via checkout_task. Call when done with the task or if you need to hand it off. The lock is also released automatically when it expires.

NameTypeReqDescription
task_idstringyesTask ID to release.

No output schema declared.

No examples provided.

Common questions

What is the io.github.entire-vc/evc-mesh-mcp server?

io.github.entire-vc/evc-mesh-mcp is listed in the public MCP registry as io.github.entire-vc/evc-mesh-mcp. Tasks, comments, shared memory and handoffs for teams of people and AI agents, over MCP. This page covers its container image (ghcr.io/entire-vc/evc-mesh-mcp:0.1.5).

Is the io.github.entire-vc/evc-mesh-mcp server safe to use?

io.github.entire-vc/evc-mesh-mcp scores 44 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the io.github.entire-vc/evc-mesh-mcp server expose?

io.github.entire-vc/evc-mesh-mcp exposes 63 tools: add_comment, add_dependency, add_vcs_link, assign_task, checkout_task, and 58 more. Their descriptions and schemas cost roughly 11,163 tokens of context every time the server is loaded.

Is the io.github.entire-vc/evc-mesh-mcp server still maintained?

io.github.entire-vc/evc-mesh-mcp is still listed as active in the MCP registry. We last reached this channel on 2 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the io.github.entire-vc/evc-mesh-mcp server under?

io.github.entire-vc/evc-mesh-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.