YouGile MCP with mutation confirmation
yougile-mcp
A Go MCP server for YouGile with 24 tools where mutating operations require confirmation and are written to an audit log
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Mutating tools change tasks, boards and stickers, but ask for confirmation before running
- The API key is stored in a local config file with 600 permissions
Install
Manual install
make build && cp bin/yougile-mcp ~/.local/bin/Build the Go binary from source.
This is third-party code. Review the repository files before installing.
What it does
The server is written in Go with domain, infrastructure and service layers, and an HTTP client with retries and rate limiting. Of 24 tools, some are read-only and run without confirmation: listing projects, boards, columns, tasks, a board summary, goal progress, and review compression. Others change data and, in the pi client, ask for confirmation first: creating a task with subtasks, a board, a column, a sticker, sending a message to a task's chat, updating and soft-deleting a task, bulk moving tasks and bulk setting stickers. Every mutation is written to a JSONL audit log. The server can run as a regular stdio MCP or as a daemon with one shared HTTP transport and rate limit for all clients.
Who it is for. For people who need an agent to never change YouGile tasks without explicit confirmation and to leave a change log
Good fit when
- You need strict change control: confirmation before creating, updating or deleting
- You need a board summary or goal progress tracking with weighted key results
- Several agents use YouGile through one daemon with a shared request limit
Not a fit when
- You want a one-command npm install: here you need to build a Go binary
- Your main MCP client does not support a tool confirmation mechanism
Example request
Show the project board summary and the list of overdue tasks, and do not change anything without confirmationLimitations
The repository has no README and no stars, with a single author. Documentation in USAGE.md and AGENTS.md targets the author's personal pi agent specifically; other MCP clients need to adapt the connection path themselves. The key is stored in a config file rather than an environment variable, requiring a manual migration via the init command.
How to disable. Remove the binary from ~/.local/bin, the config file at ~/.config/yougile-mcp/config.json, and the server entry from your MCP client.
MCP
- Transport
- stdio, http
- Authentication
- API key
| Environment variables | |
|---|---|
| YOUGILE_API_KEY required, secret | YouGile API key, used once by yougile-mcp init to create the config file |
Security check
- Mutating tools change tasks, boards and stickers, but ask for confirmation before running
- The API key is stored in a local config file with 600 permissions
README in short
There is no README, but USAGE.md describes in detail the install for the author's personal pi agent: building the binary, installing the pi-extension, migrating the key from an environment variable to a config file via the init command, the list of 24 tools split into reads and confirmed mutations, and example requests like a board summary or checking overdue tasks.
FAQ
Do all tools require confirmation?
No, read tools like lists and summaries run without asking; confirmation is only required for mutations: create, update, delete, bulk operations.
Can it run as one process for several agents?
Yes, yougile-mcp serve starts a daemon with a shared rate limit and Streamable HTTP on /mcp.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail