plugin — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited plugin (MCP Server) and scored it 87/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 3 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 3 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The most complete [Harvest](https://www.getharvest.com/) integration for Claude. 54 tools covering all important endpoints of the Harvest API v2 — time entries, projects, tasks, clients, expenses, team assignments, and reports.
Built in TypeScript (not Python like most MCP servers for Harvest time tracking), bundled into a single file — no runtime dependencies to install.
Works with Claude Desktop Extension (one-click install, no config files), Claude Cowork Plugin (skills + slash commands), and Claude Code.
harvest-mcp.mcpb from the latest release.mcpb file (or drag it into Claude Desktop settings)That's it. No terminal, no JSON files, no build steps. The extension installs the MCP server locally and handles everything — much simpler than servers that require manually editing JSON config files.
This is all you need to get started. The Cowork plugin below is optional but recommended.
harvest-plugin.zip from the latest releaseharvest-plugin.zip fileThe plugin adds slash commands (/log-time, /timer, /weekly-report, /catchup, /unsubmitted) and skills for time management, project analysis, and context-aware Harvest conventions.
Track Time — create, update, and delete time entries. Start and stop timers. Log hours manually or with start/end times.
Manage Projects — create projects, assign users, set budgets, configure billing. Full CRUD on projects, tasks, and clients.
Track Expenses — log expenses by category, manage expense categories with unit-based pricing (e.g. mileage).
Get Reports — time reports by client/project/task/team, expense reports, project budget reports, uninvoiced amounts.
Team Management — assign users to projects, manage roles and rates, view project assignments.
| Area | Tools |
|---|---|
| Time Entries | list_time_entries get_time_entry create_time_entry update_time_entry delete_time_entry restart_timer stop_timer |
| Projects | list_projects get_project create_project update_project delete_project list_project_task_assignments |
| Tasks | list_tasks get_task create_task update_task delete_task |
| Clients | list_clients get_client create_client update_client delete_client |
| Users | get_me get_user list_users list_my_project_assignments list_user_project_assignments |
| Expenses | list_expenses get_expense create_expense update_expense delete_expense |
| Expense Categories | list_expense_categories get_expense_category create_expense_category update_expense_category delete_expense_category |
| Project User Assignments | list_all_user_assignments list_project_user_assignments get_project_user_assignment create_project_user_assignment update_project_user_assignment delete_project_user_assignment |
| Time Reports | time_report_by_clients time_report_by_projects time_report_by_tasks time_report_by_team |
| Expense Reports | expense_report_by_clients expense_report_by_projects expense_report_by_categories expense_report_by_team |
| Other Reports | project_budget_report uninvoiced_report |
| Prompt | What it does |
|---|---|
log-time | Walks you through picking a project, task, hours, and notes |
weekly-summary | Summarizes the week's entries by project/client with gap detection |
timer | Quick start/stop/status for running timers |
git clone https://github.com/mikkokam/harvest-cowork-mcp.git
cd harvest-cowork-mcp
pnpm installpnpm build # Compile TypeScript + bundle with esbuild
pnpm validate # Validate the .mcpb manifest
pnpm pack:mcpb # Build + package as .mcpb extensionexport HARVEST_ACCESS_TOKEN="your-token"
export HARVEST_ACCOUNT_ID="your-account-id"
node packages/mcp-server/dist/index.mjsOr add to Claude Desktop / Claude Code config manually:
{
"mcpServers": {
"harvest": {
"command": "node",
"args": ["/absolute/path/to/harvest-cowork-mcp/packages/mcp-server/dist/index.mjs"],
"env": {
"HARVEST_ACCESS_TOKEN": "your-token",
"HARVEST_ACCOUNT_ID": "your-account-id"
}
}
}
}harvest-cowork-mcp/
├── packages/
│ ├── mcp-server/
│ │ ├── src/
│ │ │ ├── index.ts # Server entry point
│ │ │ ├── harvest-client.ts # Harvest API v2 HTTP client
│ │ │ ├── types.ts # TypeScript types for all API entities
│ │ │ ├── tools/
│ │ │ │ ├── time-entries.ts # 7 tools
│ │ │ │ ├── projects.ts # 6 tools
│ │ │ │ ├── tasks.ts # 5 tools
│ │ │ │ ├── clients.ts # 5 tools
│ │ │ │ ├── users.ts # 5 tools
│ │ │ │ ├── expenses.ts # 5 tools
│ │ │ │ ├── expense-categories.ts # 5 tools
│ │ │ │ ├── project-user-assignments.ts # 6 tools
│ │ │ │ └── reports.ts # 10 tools
│ │ │ └── prompts/
│ │ │ ├── log-time.ts
│ │ │ ├── weekly-summary.ts
│ │ │ └── timer.ts
│ │ ├── manifest.json # .mcpb extension manifest
│ │ ├── package.json
│ │ └── tsconfig.json
│ └── plugin/ # Claude Cowork plugin (skills + commands)
├── package.json # Workspace root
├── pnpm-workspace.yaml
└── .gitignoreThe pattern is consistent across all tools:
types.ts (entity interface, create/update params, list params)harvest-client.tstools/ with registerXTools() functionindex.tsmanifest.json (tool name + description)pnpm buildBuilt on Harvest API v2. Covers:
This entire MCP server — 54 tools, types, client, manifest, packaging — was built in a single session using Claude Cowork with the Claude Code VS Code Extension. Claude read the Harvest API docs, wrote all the code, validated the manifest, built the .mcpb, and pushed to GitHub. No config files were edited by hand.
MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.