Mcp Public — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Mcp Public (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The official Model Context Protocol server for [Tallyfy](https://tallyfy.com), the workflow and process automation platform. It lets any MCP-capable AI assistant run your operations: create and track tasks, launch and advance processes, read and edit templates, fill form fields, manage people and groups, and search across your organization, all through your own authenticated Tallyfy account.
This repository is an automatically published, read-only mirror. The canonical source is maintained privately by Tallyfy and a sanitized, server-only snapshot is published here on every production release. Please do not open pull requests against this mirror (they cannot be merged here). For bugs or feature requests, use the issue tracker or contact us (see Support). Hosting, deployment, and monitoring code is intentionally not part of this mirror.
Tallyfy runs a managed remote server. You do not need to host anything. Point your MCP client at:
https://mcp.tallyfy.com/Transport is streamable HTTP and authentication is OAuth against your Tallyfy account, so the assistant only ever sees data the signed-in user is allowed to see.
<details> <summary>Example client config</summary>
{
"mcpServers": {
"tallyfy": {
"type": "streamable-http",
"url": "https://mcp.tallyfy.com/"
}
}
}</details>
108 tools across the Tallyfy domain, grouped by area:
| Area | Examples |
|---|---|
| Tasks | create, complete, reassign, comment on, and search tasks |
| Processes (runs) | launch a process from a template, advance and track steps |
| Templates (checklists) | read, create, and edit templates and their steps |
| Form fields | read and populate kick-off and step form fields |
| Automation | inspect and manage automated actions / rules |
| People & access | users, groups, guests, organization membership |
| Organization | tags, folders, comments, search across the org |
Every tool calls the public Tallyfy API on behalf of the authenticated user. There are no write operations the signed-in user could not perform in the Tallyfy app directly.
You can build and run the server from this mirror with Docker:
cd server
cp ../.env.example .env # then fill in the values you need
docker build -t tallyfy-mcp-server .
docker run --rm -p 9000:9000 --env-file .env tallyfy-mcp-serverThe server listens on port 9000 and speaks streamable HTTP at /. See .env.example for configuration. Python 3.11 is required if you prefer to run it without Docker (pip install -r server/requirements.txt, then uvicorn server:app from inside server/).
com.tallyfy/mcp-server)Tools are scoped to the authenticated user, inputs are validated and the outbound API surface is allowlisted. We disclose no static credentials in this repository: all secrets are supplied at runtime via environment variables. If you find a security issue, please email [email protected] rather than opening a public issue.
Apache License 2.0 © Tallyfy, Inc.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.