C1 Identity & least privilege
Minimal 0.05 / 1.00
Task Master runs as a local stdio process with the operator's full user authority and whatever provider API keys are placed in the MCP environment or a project .env file. Nothing narrows that authority: tools accept any absolute project directory, and spawned provider CLIs inherit the whole environment. There is no per-tool or per-request credential scoping. The keys it holds are LLM-provider keys, so the damage is mostly spend and local file changes rather than access to production systems.
C2 Approval gates
Minimal 0.45 / 1.00
As an MCP tool server, Task Master leaves approval to the host but labels its tools: every tool carries a read-only or destructive hint, and reads and writes are separate tools. There are no previews or dry runs for destructive operations and no server-enforced read-only mode. Writes are mostly to task files, but some tools overwrite files at caller-chosen paths or create git commits of all changes, with no undo of their own.
C3 Tool & action scoping
Minimal 0.45 / 1.00
Tools are narrow task-management operations with typed zod schemas, which keeps designed use small. Path arguments are not contained: the project root, research file paths and the parse_prd output path all accept any absolute path. The default loads all tools, including write, git and network-backed research tools, though tool groups can be selected with an environment variable.
C4 Code-execution isolation
Minimal 0.00 / 1.00
With the default Anthropic API provider, Task Master runs no model-written code. It also ships providers that launch coding-agent CLIs (Claude Code, Codex, Gemini CLI, Grok CLI), and the models tool lets the host model switch to them. Those CLIs run on the host as the same user with the full environment, including every API key, and Task Master adds no isolation around them.
C5 Untrusted input blast radius
Minimal 0.13 / 1.00
Task Master turns PRDs, project files and Perplexity web research into tasks that the host coding agent then reads and follows, with nothing marking which text came from untrusted sources. Responses wrap data in a JSON envelope with version and tag metadata, but task content carries no provenance. Assume a hijacked host: it can send any readable file to the research provider or point model calls at another endpoint through the models tool, but destructive changes are limited to task data and git commits.
C6 Memory, context & configuration integrity
Minimal 0.10 / 1.00
Task Master keeps tasks, research notes and settings as project files that the host agent reads back in later sessions, and the task text it stores is built from model output, PRDs and web research. It loads the project's .taskmaster configuration and .env files from the workspace on every call without any trust decision, and those files choose the model provider and security-relevant endpoints and settings. Nothing validates or tags what is persisted.
C7 Third-party extensions
Minimal 0.07 / 1.00
Task Master does not install plugins, but its agent-CLI providers launch whatever claude, codex, gemini or grok binary is on the user's PATH, with no version pinning or verification. Project configuration or the models tool can switch to these providers without a separate consent step. The launched CLI runs as the same user with the full environment.
C8 Secrets & sensitive-data protection
Minimal 0.20 / 1.00
Provider keys come from the MCP environment or a project .env file and are held in process memory. Anonymous telemetry to Sentry is on by default and, as the changelog documents, records AI prompts and responses and MCP tool interactions, with default PII sending enabled. Error-message redaction exists only on the CLI path. A stored Hamster session, if the user logs in, is written with owner-only permissions.
C9 Audit & traceability
Minimal 0.25 / 1.00
Task Master writes no audit record of its own for most tool calls; it sends log lines to the host over MCP and to stderr. The autopilot workflow appends structured events to an activity.jsonl file under the user's home directory, which covers only that workflow. Sentry spans are telemetry, not an audit trail.
C10 Limits & kill switch
Minimal 0.33 / 1.00
Each model call has a per-role token limit and at most two retries, research file context is capped at 50KB, and the Grok CLI provider has a timeout that kills the process. There is no cost ceiling and no limit on how many model calls a bulk operation such as expand_all makes. Defaults can be raised from project configuration.