WEEEK MCP with confirm-gated writes
weeek-mcp
A WEEEK MCP server that is read-only by default: tasks, attachments and comments via a browser session, writes are opt-in
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- With writes enabled, can create, change and delete tasks in allowed projects
- Reads comments through an imported browser session rather than the official API
Install
Manual install
git clone https://github.com/prod-broke-again/weeek-mcp.git && cd weeek-mcp && npm install && npm run buildInstall from the README; then a .env with WEEEK_API_TOKEN and optional write settings.
This is third-party code. Review the repository files before installing.
What it does
The server reads WEEEK projects, boards, columns and tasks, searches and filters them, including my open tasks, reads members and tags, and reads image, txt, md, json and csv attachments. Task comments are not exposed by WEEEK's public API, so the server reads them through an imported browser session. Write tools (create, edit, move, delete a task) are off by default and require a mandatory propose-then-wait-for-confirmation-then-confirm cycle, plus a WEEEK_ALLOW_WRITE variable and an allowed-project list. WEEEK's Docs and Wiki are outside the public API and are not read; here, documents mean only task attachments.
Who it is for. For people who want to connect WEEEK to an agent safely: read-only first, with writes enabled separately and only on chosen projects.
Good fit when
- You want a safe start: an agent reads tasks but cannot change them until you explicitly allow it
- You need task comments, which are missing from WEEEK's public API
- You want to restrict writes to specific projects via an allowlist
Not a fit when
- You need WEEEK Docs and Wiki rather than just task attachments, the public API does not expose them
- You need text extraction from PDF or DOCX attachments, v1 only supports URL and text files
Example request
Show my open tasks in the portal project and the latest comments on the most urgent oneLimitations
Comments are read only through an imported browser session, not the public API. PDF and DOCX attachments do not get text extracted, only URL and text files. Writes are off by default and need explicit WEEEK_ALLOW_WRITE, a list of allowed projects, and confirmation for every action. Requires Node.js 20 or newer.
How to disable. Remove the server from your MCP client configuration and delete the .env with the token and saved session.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| WEEEK_API_TOKEN required, secret | The WEEEK workspace token from settings. |
| WEEEK_ALLOW_WRITE | Enables write tools, defaults to false. |
| WEEEK_WRITE_PROJECTS | An allowlist of project ids where writes are permitted. |
| WEEEK_READ_ONLY_PROJECTS | An allowlist of project ids for reading, defaults to all. |
Security check
- With writes enabled, can create, change and delete tasks in allowed projects
- Reads comments through an imported browser session rather than the official API
README in short
The README gives a can/cannot table: projects, boards, tasks and search yes, WEEEK Docs and Wiki no, task writes are opt-in with explicit confirmation, comments are read through a browser session, and PDF/DOCX text extraction is not yet supported. A separate environment variable table covers the token, project aliases, read and write allowlists, an attachment size cap, a directory cache TTL and a requests-per-second limit.
FAQ
Can the agent delete a task without asking?
No, write tools are off by default and require mandatory user confirmation plus WEEEK_ALLOW_WRITE enabled.
Does the server read WEEEK's wiki and docs?
No, WEEEK's public API does not expose them; the server only reads task attachments of certain formats.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI