ytcli: Yandex Tracker and Wiki CLI for agents
ytcli
A CLI and skill for Yandex Tracker and Wiki: short output readable by people and agents alike, instead of raw MCP payloads costing thousands of tokens
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Write commands change issues, comments, attachments and Wiki pages in the live organization
- There is a separate read and write allowlist, but it only guards calls through the CLI itself, not raw credentials in the environment
- Start with a read-only allowlist (get, find, count) and keep write verbs in confirm mode
Install
Manual install
brew install ormeilu/tap/ytcliA prebuilt binary with shell completions via Homebrew.
This is third-party code. Review the repository files before installing.
What it does
ytcli is a Rust binary covering nearly the whole public Tracker API (issues, worklogs, timers, checklists, links, queues, boards, sprints, projects, portfolios, goals, attachments) and the organization's Wiki (pages, comments, files, dynamic tables). The author's core idea: a typical MCP server burns tens of thousands of context tokens before the first question and answers with raw payloads; ytcli costs nothing until called and answers in about fifteen lines. Sign-in is a short device code with no app registration and no token file: ytcli auth login --device prints a code, confirmation happens in a browser, and the token goes straight into the OS keychain. A separately installed skill teaches an agent the tool: read verbs (get, find, count) can be permanently allowed, while write verbs need confirmation, because reads and writes never share a command prefix.
Who it is for. For teams on Yandex Tracker and Wiki who want to give an agent token-cheap access with a clean split between reading and writing.
Good fit when
- Saving context tokens compared to a typical MCP server matters
- You want a static permission allowlist that does not need updating as the tool evolves
- You need both issue tracking and corporate Wiki access from one tool
Not a fit when
- You specifically need the MCP protocol rather than a CLI: ytcli works as an ordinary terminal command
- Your organization does not allow third-party OAuth apps: then only pasting an existing token works
Example request
Show my open issues in the PROJ queue and comment on PROJ-1 that it is deployed to stagingLimitations
The binary and the skill are installed separately: the skill without the binary is documentation for a command that is not there. A Yandex Tracker organization ID is required. The full list of ruled-out features and reasons is in the project's docs/TODO.md.
How to disable. Run ytcli auth logout --account name and remove the plugin/skills/ytcli folder from your agent's skills directory.
Security check
- Write commands change issues, comments, attachments and Wiki pages in the live organization
- There is a separate read and write allowlist, but it only guards calls through the CLI itself, not raw credentials in the environment
- Start with a read-only allowlist (get, find, count) and keep write verbs in confirm mode
README in short
The README explains the tool's philosophy in depth (a cheap call instead of expensive MCP context), install paths for the binary via Homebrew, uv or cargo, device-code sign-in into the keychain, separately installing the skill for around 75 agents or as a Claude Code plugin, working with issues and Wiki for both a person and an agent, the read/write allowlist format, and the full procedure for installing it for someone else while handing credentials and the allowlist back to them.
FAQ
Where does the token go after sign-in?
Into the OS keychain, not a file on disk, along with everything needed to renew it.
Can the agent accidentally change something?
Read verbs like get and find cannot write at all, and write verbs always sit in a separate ask allowlist that requires confirmation.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI