# io.github.entire-vc/evc-mesh-mcp (mcpb · evc-mesh-mcp-0.1.5.mcpb)

Tasks, comments, shared memory and handoffs for teams of people and AI agents, over MCP.

- Trust score: 39/100 (low)
- Change this week: +30
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-02

## Components

- remote · `mesh.entire.host`: 37/100, [markdown](https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/mesh.md), [page](https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/mesh)
- remote · `mesh.entire.host`: 33/100, [markdown](https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/mesh-2.md), [page](https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/mesh-2)
- mcpb · `evc-mesh-mcp-0.1.5.mcpb`: 39/100 (this document), [markdown](https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/https-github-com-entire-vc-evc-mesh-mcp-releases-download-v0-1-5-evc-mesh-mcp-0.md), [page](https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/https-github-com-entire-vc-evc-mesh-mcp-releases-download-v0-1-5-evc-mesh-mcp-0)
- oci · `ghcr.io/entire-vc/evc-mesh-mcp:0.1.5`: 44/100, [markdown](https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/ghcr-io-entire-vc-evc-mesh-mcp-0-1-5.md), [page](https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/ghcr-io-entire-vc-evc-mesh-mcp-0-1-5)

## Channel facts

- Registry: `mcpb`
- Package: `https://github.com/entire-vc/evc-mesh-mcp/releases/download/v0.1.5/evc-mesh-mcp-0.1.5.mcpb`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-02.

- **Supply Chain Security**: 0/100
  - No malware scan is available for this kind of package: the supply-chain vendors we use do not cover it. This is a permanent gap in our coverage, not a finding about the package.
  - Known CVEs could not be checked: we found no dependency list to check in this bundle: either it runs a compiled binary, whose bundled manifests we do not read, or none of the package.json, requirements.txt, pyproject.toml or uv.lock files it ships for its runtime declares a dependency we can read (a requirements.txt that only points at a setup.py project, a local path, or a nested requirements file we cannot follow counts as none).
  - Install-script risk not yet assessed.
  - Dependency health could not be checked: we found no dependency list to check in this bundle: either it runs a compiled binary, whose bundled manifests we do not read, or none of the package.json, requirements.txt, pyproject.toml or uv.lock files it ships for its runtime declares a dependency we can read (a requirements.txt that only points at a setup.py project, a local path, or a nested requirements file we cannot follow counts as none).
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 8 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 69/100
  - AI-judged instruction clarity (excellent).
  - Context-footprint check failed: tool/resource definitions use about 5443 tokens (~217/item across 25 items; 25 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 25 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

**Unverified: 2 categories.** Categories scored 0 because we could not verify them: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### How do I install the io.github.entire-vc/evc-mesh-mcp server?

io.github.entire-vc/evc-mesh-mcp ships as an MCPB bundle, a single file you download and open in an MCP host that supports MCPB bundles, such as Claude Desktop. The host reads the launch command from the bundle's own manifest, so there is no command to copy. The MCP registry declares no SHA-256 for this bundle, so there is no published digest to check the download against.

- Download bundle: `https://github.com/entire-vc/evc-mesh-mcp/releases/download/v0.1.5/evc-mesh-mcp-0.1.5.mcpb`

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-10-01 (score 39, +30)

- [security improvement] Injection markers: unverified → pass
- [security] First check of Judged manipulation: pass
- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] MCP protocol: unverified → pass
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 100
- [functional] First check of Destructive annotations: 100
- [functional] First check of Schema quality: fail
- [functional] First check of Schema quality: excellent

### 2026-09-28 (score 9, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-25 (score 9, −4)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 13)

First indexed and scored.

## MCP tools (25)

### `add_comment` (~305 tokens)

Add a comment to a task. If the body @-mentions someone, the response carries a `delivery` array — one entry per mentioned handle — reporting whether it actually reached a path they consume (their task queue, a notification) or was skipped/failed and why; a `hint` field suggests the fix when there is one (e.g. assign the task). Omitted entirely when the comment mentions nobody.

Input parameters:

- `body` (string, required): Comment body (markdown supported).
- `is_internal` (boolean): Mark as internal (agent-only visible).
- `metadata` (object): Additional metadata as key-value pairs. Set {"informational": true} on a comment you write on a task that is ALREADY done/cancelled when your comment needs no action from its assignee — a plain ackno…
- `parent_comment_id` (string): Parent comment ID for threading.
- `task_id` (string, required): Task ID.

### `add_vcs_link` (~439 tokens)

Link a task to a pull request, commit, or branch. This is what makes the task↔PR join real: a task with no VCS link cannot be matched to the code that implements it, so PR-driven status automation and any 'what shipped for this task?' report simply will not see it. Call it as soon as the PR exists. Only task_id and url are needed — provider, link_type and external_id are inferred from a GitHub or GitLab URL. If the PR is ALREADY merged (or closed) by the time you call this — e.g. you finished, merged, and are linking retroactively — pass status='merged' (or 'closed'). Without it the link starts as 'open' and the done-evidence gate will block move→done on it forever: no GitHub webhook fires for a merge that happened before the link existed.

Input parameters:

- `external_id` (string): PR number, commit SHA, or branch name. Inferred from the URL; only needed when the URL is not a recognised PR/commit/branch link.
- `link_type` (string): What the URL points at: pr (alias: pull_request), commit, branch. Inferred from the URL path; defaults to pr.
- `provider` (string): VCS provider: github, gitlab. Inferred from the URL host; defaults to github.
- `status` (string): PR status, if you already know it: open, merged, closed. Pass 'merged' when linking a PR that was merged before this call — that is the one case a webhook can never backfill. Omit it to let the link…
- `task_id` (string, required): Task ID.
- `title` (string): Human-readable label, e.g. the PR title.
- `url` (string, required): Link URL, e.g. https://github.com/owner/repo/pull/123.

### `assign_task` (~75 tokens)

Assign a task to a user or agent.

Input parameters:

- `assign_to_self` (boolean): Assign to the calling agent.
- `assignee_id` (string): Assignee UUID. Omit to unassign.
- `assignee_type` (string): Assignee type: user, agent.
- `task_id` (string, required): Task ID.

### `create_task` (~254 tokens)

Create a new task. Check get_my_tasks and list_tasks FIRST to avoid duplicates. Set status_slug for initial status (defaults to project's first status).

Input parameters:

- `assignee_id` (string): Assignee ID (user or agent UUID).
- `assignee_type` (string): Assignee type: user, agent.
- `custom_fields` (object): Custom field values as key-value pairs.
- `delegation_level` (string): Delegation level: auto, review, supervised.
- `description` (string): Task description.
- `due_date` (string): Due date in RFC3339 format.
- `estimated_hours` (number): Estimated hours for the task.
- `labels` (array): Task labels.
- `parent_task_id` (string): Parent task ID for subtask.
- `priority` (string): Priority: urgent, high, medium, low, none.
- `project_id` (string, required): Project ID.
- `start_after` (string): Don't surface/feed this task before this RFC3339 timestamp (e.g. a scheduled retry). Independent of due_date.
- `status_slug` (string): Status slug (e.g. 'todo'). Uses project default if omitted.
- `title` (string, required): Task title.

### `forget` (~37 tokens)

Delete a memory entry. Agents can only delete their own agent-scope memories.

Input parameters:

- `memory_id` (string, required): UUID of the memory to delete.

### `get_canonical_updates` (~137 tokens)

Fetch canonical decisions broadcast since a given time. Call at ACP step 6 (session start) to catch up on owner directives since your previous session. Returns only privacy:public records targeted at you or all agents.

Input parameters:

- `agent` (string): Your agent slug (e.g. 'alice'). Used to filter propagate_to:<slug> records. Omit to get only propagate_to:all records.
- `scope` (string): Optional project UUID to restrict to project-scoped decisions.
- `since` (string): RFC3339 cursor. Defaults to your previous session's start time (server-resolved). Omit on first call.

### `get_context` (~120 tokens)

Get RECENT ACTIVITY for a project (last 24h by default): event stream with summaries, decisions, errors, plus accumulated project knowledge. Use for ACP Step 4 — what happened recently. For searching specific knowledge, use recall.

Input parameters:

- `event_types` (array): Filter by event types.
- `limit` (number): Max events to return (default 50).
- `project_id` (string, required): Project ID.
- `since` (string): Only events after this timestamp (RFC3339).
- `tags` (array): Filter by tags.

### `get_my_rules` (~64 tokens)

Get ALL governance rules that apply to you: workflow constraints, assignment policies, behavioral requirements. Includes workspace and project-level rules with source annotations. Call at session start (ACP Step 3).

Input parameters:

- `project_id` (string): Optional project ID to get project-specific effective rules.

### `get_my_tasks` (~93 tokens)

Get YOUR assigned tasks (ACP Step 5). Filter by status_category to focus on active work. Use at session start and after completing tasks to pick up the next assignment.

Input parameters:

- `limit` (number): Max results (default 50).
- `project_id` (string): Filter by project.
- `status_category` (string): Filter by status category: backlog, todo, in_progress, review, done, cancelled.

### `get_project_knowledge` (~152 tokens)

Get ALL PERMANENT KNOWLEDGE for a project: decisions, conventions, accumulated context. Call at session start (ACP Step 2). Returns workspace-level + project-level memories. For RECENT events, use get_context instead.

Input parameters:

- `limit` (number): Max workspace-tier memories (default 100, max 500).
- `min_importance` (number): Minimum importance_score for workspace-tier (default 0 = all).
- `offset` (number): Pagination offset for workspace-tier (default 0).
- `project_id` (string, required): Project UUID.
- `tags_any` (string): Comma-separated tag OR-filter for workspace-tier, e.g. 'kind:decision,kind:incident'.

### `get_task` (~136 tokens)

Get full task details with optional comments, artifacts, dependencies, and VCS links.

Input parameters:

- `include_artifacts` (boolean): Include artifacts.
- `include_comments` (boolean): Include comments.
- `include_dependencies` (boolean): Include dependencies.
- `include_vcs_links` (boolean): Include linked PRs/MRs/commits/branches (id, provider, link_type, external_id, url, status, created_at) — use this instead of a raw REST call to diagnose a misclassified or stuck-status link.
- `task_id` (string, required): Task ID (full UUID or 6–12 char hex short-ID prefix).

### `get_task_context` (~61 tokens)

Get EVERYTHING about ONE TASK in a single call: full details + comments + artifacts + dependencies + activity. Use when working on a specific task instead of calling get_task + list_comments + list_artifacts separately.

Input parameters:

- `task_id` (string, required): Task ID.

### `heartbeat` (~112 tokens)

Send heartbeat to stay visible. Call at session START with status=online, periodically during work with status=busy. Reports current_task_id, message, and metadata.

Input parameters:

- `current_task_id` (string): ID of the task currently being worked on.
- `message` (string): Short human-readable status message (e.g. 'running tests', 'waiting for review').
- `metadata` (object): Arbitrary JSON metadata to store with the heartbeat.
- `status` (string): Agent status: online, busy, error.

### `list_projects` (~43 tokens)

List available projects in the workspace.

Input parameters:

- `include_archived` (boolean): Include archived projects.
- `workspace_id` (string): Workspace ID. Defaults to agent's workspace.

### `list_tasks` (~537 tokens)

List tasks with filters. Provide project_id for project-scoped listing or workspace_id for global search across all projects (requires search parameter). Each item's description is included by default and has_description always reflects the task's real content, computed before any trimming below — but on ANY page (plain listing or search=) whose descriptions total more than 200KB, the server blanks descriptions from the TAIL of that page (in item order) to keep the response size bounded, and marks the response truncated:true (field omitted when false). search= usually returns few enough hits to stay under that budget, so it is the practical workaround for a specific known task, but the one guaranteed way to read a given task's full description regardless of any listing's size or order is get_task(task_id).

Input parameters:

- `assignee_type` (string): Filter by assignee type: user, agent, unassigned.
- `labels` (array): Filter by labels.
- `limit` (number): Max results to return (default 50, max 200).
- `list_revision` (number): The list_revision echoed back on a previous page of this same project-scoped walk (see the response's list_revision field). Pass it back to continue that walk. If the project's tasks changed since th…
- `order` (string): Sort direction: asc (default) or desc. Without this, a project larger than `limit` returns its OLDEST tasks, so "what changed recently" walks come back empty and look clean. An invalid value is REFUS…
- `page` (number): 1-based page number (default 1). The response reports total_pages; without this parameter every page beyond the first was unreachable while the envelope kept advertising them.
- `priority` (string): Filter by priority: urgent, high, medium, low, none.
- `project_id` (string): Project ID (required unless workspace_id is provided).
- `search` (string): Search in title and description.
- `sort` (string): Sort field: created_at, updated_at, priority, due_date.
- `status_category` (string): Filter by status category: backlog, todo, in_progress, review, done, cancelled.
- `workspace_id` (string): Workspace ID for global cross-project search (requires search parameter).

### `move_task` (~144 tokens)

Change task status (e.g. todo → in_progress → done). Use status SLUGS (not UUIDs). On move to 'review', task auto-reassigns to creator unless assignee_id is provided.

Input parameters:

- `assignee_id` (string): Reassign to this agent/user on move. Overrides auto-reassign to creator on review.
- `assignee_type` (string): Assignee type if assignee_id is set: user or agent.
- `comment` (string): Optional comment to add when moving.
- `status_slug` (string, required): Target status slug (e.g. 'in_progress', 'done').
- `task_id` (string, required): Task ID.

### `publish_event` (~172 tokens)

Publish an event to the event bus. For summaries, use event_type='summary'. Add memory={persist:true, key:'decision-name'} to also save as permanent memory. Replaces the deprecated publish_summary tool.

Input parameters:

- `event_type` (string, required): Event type: summary, status_change, context_update, error, dependency_resolved, custom.
- `memory` (object): Optional memory hint to persist alongside the event (e.g. key decisions, conventions).
- `payload` (object, required): Event payload as key-value pairs.
- `project_id` (string, required): Project ID.
- `subject` (string, required): Event subject line.
- `tags` (array): Event tags for filtering.
- `task_id` (string): Related task ID.
- `ttl_hours` (number): Time-to-live in hours (default 24).

### `recall` (~497 tokens)

SEARCH memory by keywords. Use to find a SPECIFIC piece of knowledge, e.g. 'API convention' or 'license decision'. Returns ranked results with scores. For loading ALL project knowledge at session start, use get_project_knowledge instead. Set include_archived=true to retrieve archived memories.

Input parameters:

- `apply_recency_decay` (boolean): Sort by relevance * 0.95^days_since_created.
- `created_by` (string): Filter by agent ID (UUID).
- `include_archived` (boolean): Include archived memories in results (default false).
- `include_expired` (boolean): Include expired memories (default false).
- `limit` (number): Max results (default 10, max 50). This is a hard bound: the response never contains more than limit items. When knowledge-graph boost is enabled, a share of the page (limit/4, at least 1 when limit>=…
- `min_importance` (number): Minimum importance_score threshold (0-1, default 0.3 — matches the lowest score the server assigns, kind:session-checkpoint, so prior-session hand-offs are returned without an override). Raise it to…
- `offset` (number): Pagination offset (default 0).
- `order_by` (string): Sort order: created_at:desc (default), created_at:asc, relevance:desc, decayed_relevance:desc.
- `project_id` (string): Filter to a specific project.
- `query` (string, required): Full-text search query.
- `relevance_min` (number): Minimum relevance score (0-1).
- `scope` (string): Filter by scope: workspace, project, agent, or all (default).
- `since` (string): Return memories created at or after this RFC3339 timestamp.
- `tags` (array): AND-filter: memory must contain ALL listed tags.
- `tags_any` (array): OR-filter: memory must contain AT LEAST ONE of these tags.
- `until` (string): Return memories created at or before this RFC3339 timestamp.

### `recall_with_graph` (~149 tokens)

Search memory with Knowledge Graph expansion. Seeds from hybrid recall, then BFS-traverses memory_edges up to hops depth. Returns memories ranked by composite score with hop_distance and provenance fields. Use when you want broader context — related decisions, connected incidents, derived learnings.

Input parameters:

- `hops` (number): Graph traversal depth (default 2, max 5).
- `project_id` (string): Filter to a specific project.
- `q` (string, required): Search query (keywords or natural language).
- `task_id` (string): Optional task ID — used as cache key discriminator for session-scoped traversal.
- `weight_threshold` (number): Minimum edge weight to follow (default 0.3).

### `record_owner_decision` (~311 tokens)

Record a directive from the workspace owner as a canonical decision in project_knowledge. Broadcasts to specified agents via propagate_to tags. privacy:private records are stored but EXCLUDED from get_canonical_updates. Auto-flags private if text contains secrets. If task_id is given, also records this as a human_gate decision on that task (docs/human-gate-decision-recorded.md in evc-mesh) — releases the gate as a consequence if it's currently live, and links back via canonical_key. Best-effort: a failure here is reported in the result but does not undo the canonical write.

Input parameters:

- `privacy` (string): 'public' (default, visible in change-feed) or 'private' (recorded but hidden).
- `propagate_to` (array): Agent slugs to propagate to, e.g. ['alice','bob']. Use ['all'] for workspace-wide broadcast.
- `scope` (string): Optional project_id UUID. Omit for workspace-level decisions.
- `summary` (string, required): One-line summary used as UPSERT key (dedupes same decision on same day).
- `task_id` (string): Optional task UUID this decision answers. When set, also records a human_gate decision on that task (provenance=attested, channel=telegram, quote=text) — releasing a live human_gate as a consequence.…
- `text` (string, required): Full text of the decision/directive.

### `remember` (~989 tokens)

Save knowledge to persistent memory. Use for decisions, conventions, preferences. UPSERT by key — calling with same key updates the existing entry. Content is screened on write and REFUSED with a named reason (never silently stripped or stored) if it contains invisible/bidi characters, an LLM role tag, an instruction to ignore previous/system instructions, a PEM private key, a prefixed API token (sk-/ghp_/xox*/AKIA), or a literal assignment to a *_PASSWORD/_SECRET/_TOKEN/_API_KEY name. LIMITATION — this screen is partial and must not be relied on as a secret filter: it CANNOT see a secret that has no recognisable prefix and no field name next to it (a bare value pasted on its own line), nor names it does not know. Do not paste credentials here on the assumption they will be caught; record where a secret lives, never its value.

Input parameters:

- `attach_context` (boolean): When false, disables auto-injection of thread_id and source_task_id. Use for cross-cutting records not tied to the active task.
- `content` (string, required): What to remember (markdown).
- `expected_version` (number): Make the write conditional: it succeeds only if the stored version still matches this number, and is REFUSED with both version numbers if someone else wrote to the key in between. Pass the version re…
- `expires_at` (string): RFC3339 timestamp or Go duration (e.g. '72h') when this memory should expire.
- `key` (string, required): Slug key for UPSERT (e.g. 'api-convention', 'license-decision'). ENFORCED server-side as ^[a-z0-9][a-z0-9-]*[a-z0-9]$ — lowercase alphanumeric and hyphens only, at least two characters, no leading or…
- `project_id` (string): Project ID (required for project scope).
- `reason` (string): Why this memory is worth writing — what a future thread should be able to do with it, or what changed if you are correcting an existing key. Recorded on the revision alongside the content, so a later…
- `relevance` (number): Relevance score 0-1 (default 1.0 when omitted). NOT the same field as importance_score: relevance is a caller-set ranking hint, importance_score is computed from tags (see tags) and is the field min_…
- `scope` (string): workspace | project | agent (default: project).
- `source_task_id` (string): UUID of the Mesh task that produced this memory. Auto-populated from the runner state file (FIDDLER_STATE_FILE) or the active checkout. Enables Amendment 2/3 KG edge hooks.
- `source_url` (string): Optional URL/path to the source of this knowledge (task ID, PR, file path).
- `tags` (array): Tags for categorization and filtering. A kind: tag also SETS importance_score, which is what decides whether recall returns this entry at its default threshold of 0.3 — so the tag you choose is a ret…
- `thread_id` (string): Thread identifier for same-session memory grouping. Auto-populated from the runner state file when omitted.

### `report_error` (~78 tokens)

Report an error encountered during work.

Input parameters:

- `error_message` (string, required): Error message.
- `recoverable` (boolean): Whether the error is recoverable.
- `severity` (string): Severity: low, medium, high, critical.
- `stack_trace` (string): Stack trace or details.
- `task_id` (string): Related task ID.

### `session_report` (~84 tokens)

Report session metrics. Call before session end. Returns compliance score and session stats.

Input parameters:

- `estimated_cost` (number): Estimated cost in USD.
- `model` (string): LLM model used (e.g. 'claude-sonnet-4').
- `tokens_in` (number): Total input tokens this session.
- `tokens_out` (number): Total output tokens this session.

### `set_project_knowledge` (~286 tokens)

Write a structured fact to project knowledge. UPSERT by key — calling with same key updates the existing entry. Use for deploy URLs, stack conventions, gotchas. These facts are visible via get_project_knowledge.

Input parameters:

- `attach_context` (boolean): When false, disables auto-injection of thread_id and source_task_id.
- `category` (string): Optional category: deploy, stack, conventions, gotchas, api, auth, etc.
- `key` (string, required): Slug key for UPSERT (e.g. 'deploy-url', 'stack-convention'). Same enforced pattern as remember: ^[a-z0-9][a-z0-9-]*[a-z0-9]$ — hyphens, NEVER colons; a colon-delimited key is REFUSED, not normalised.
- `project_id` (string, required): Project ID to store knowledge for.
- `source_task_id` (string): UUID of the Mesh task that produced this fact. Auto-populated from the runner state file when omitted.
- `source_url` (string): Optional URL/path to the source of this knowledge.
- `tags` (array): Additional tags for filtering.
- `thread_id` (string): Thread identifier. Auto-populated from the runner state file when omitted.
- `value` (string, required): The knowledge to store (markdown, max 4000 chars).

### `update_task` (~168 tokens)

Update task fields.

Input parameters:

- `completion_signal` (boolean): Mark agent-side work as finished.
- `custom_fields` (object): Custom field values to update.
- `delegation_level` (string): Routing after work: auto, review, or supervised.
- `description` (string): New description.
- `due_date` (string): Due date in RFC3339 format. Pass an empty string to clear it.
- `estimated_hours` (number): Estimated hours.
- `labels` (array): New labels.
- `priority` (string): New priority.
- `start_after` (string): Don't surface/feed this task before this RFC3339 timestamp. Independent of due_date. Pass an empty string to clear it.
- `task_id` (string, required): Task ID.
- `title` (string): New title.

## Diagnostics

Captured diagnostic sections: Provenance. The full working is on the page: https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/https-github-com-entire-vc-evc-mesh-mcp-releases-download-v0-1-5-evc-mesh-mcp-0#diagnostics

## Score history

- 2026-10-02: 39
- 2026-10-01: 39
- 2026-09-30: 9
- 2026-09-29: 9
- 2026-09-28: 9
- 2026-09-27: 9
- 2026-09-26: 9
- 2026-09-25: 9
- 2026-09-24: 13

## Common questions

### What is the io.github.entire-vc/evc-mesh-mcp server?

io.github.entire-vc/evc-mesh-mcp is listed in the public MCP registry as io.github.entire-vc/evc-mesh-mcp. Tasks, comments, shared memory and handoffs for teams of people and AI agents, over MCP. This page covers its MCPB bundle (https://github.com/entire-vc/evc-mesh-mcp/releases/download/v0.1.5/evc-mesh-mcp-0.1.5.mcpb).

### Is the io.github.entire-vc/evc-mesh-mcp server safe to use?

io.github.entire-vc/evc-mesh-mcp scores 39 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the io.github.entire-vc/evc-mesh-mcp server expose?

io.github.entire-vc/evc-mesh-mcp exposes 25 tools: add_comment, add_vcs_link, assign_task, create_task, forget, and 20 more. Their descriptions and schemas cost roughly 5,443 tokens of context every time the server is loaded.

### What licence is the io.github.entire-vc/evc-mesh-mcp server under?

io.github.entire-vc/evc-mesh-mcp declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- Repository: https://github.com/entire-vc/evc-mesh-mcp
- Changelog RSS feed: https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/https-github-com-entire-vc-evc-mesh-mcp-releases-download-v0-1-5-evc-mesh-mcp-0.xml
- Changelog JSON feed: https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/https-github-com-entire-vc-evc-mesh-mcp-releases-download-v0-1-5-evc-mesh-mcp-0.json
- HTML version of this page: https://verifymcp.io/servers/entire-vc-evc-mesh-mcp/https-github-com-entire-vc-evc-mesh-mcp-releases-download-v0-1-5-evc-mesh-mcp-0
