Dependency-graph MCP server. Tells Claude/Cursor what breaks if you change X. Provenance guards.
io.github.kimgh06/thask โ Dependency-graph MCP server
The io.github.kimgh06/thask server is a dependency-graph MCP server. It provides a way for Claude/Cursor to understand what breaks when a given change is made, and it includes provenance guards to help prevent agents from silently using hallucinated descriptions on the dependency graph.
๐ ๏ธ Key Features
Dependency-graph layer for AI-assisted development
Reports dependencies to determine what breaks when changing X
Provenance guards for the dependency graph
๐ Use Cases
Querying the dependency graph from Claude/Cursor via MCP
Impact analysis for dependency-related changes
โก Developer Benefits
Makes dependency relationships available to MCP-enabled tools
Adds provenance controls around graph information
โ ๏ธ Limitations
Described only at the level of dependency mapping and provenance guarding; no specific tool list or capabilities count provided in the source data
The dependency graph layer for AI-assisted development.
Map what depends on what, then let Claude Code / Cursor / Codex query it through MCP โ with provenance guards so agents can't silently land hallucinated descriptions on your graph.
v0.6.0 โ Knowledge OS Foundation. Thask now models the full project
memory, not just execution deps: 4 new first-class entity types
(REQUIREMENT, DECISION, EXPERIMENT, PERSON) alongside the original
7, 9 new relationship verbs (realizes, supersedes, decided,
produced, owns, reported, drives, tests, conflicts), a domain
lifecycleState orthogonal to status, and per-node comments,
attachments, and canonical project tags. Same 25 MCP tools โ the new
capabilities ride on wider enums plus two additive fields.
The file plus every node that depends_on it across your graph.
Agent answers
Plausible code. Three downstream flows quietly break.
"This change touches 3 flows and 2 UIs โ I will update them together, or stop and ask."
Description drift
Agent rewrites the "why" prose on confidence, you read it, the next agent treats it as ground truth.
Agent keys default to blocking semantic writes. They propose to a queue; a human approves. Source-of-record stays human.
Every change is recorded with 6-dimension provenance (actor, channel, agent model, mutation kind, trigger, evidence) so the next agent knows what to trust and what to re-derive from code.
Why Thask?
Spreadsheets lose context. Linear issue trackers hide relationships. Thask maps your product as a living graph โ so you can see what breaks before it breaks.
AI-Native
Ship with thask mcp serve โ Claude Code and Cursor read your dependency graph as a tool. Ask "what breaks if I change this?" and get real answers.
Graph-first Thinking
Every flow, task, and bug is a node. Every dependency is a visible edge. No more hidden connections.
Impact at a Glance
One click shows which nodes are affected by recent changes. Catch regressions before they ship.
Self-hosted
docker compose up โ that's it. Your data stays on your infrastructure. No vendor lock-in.
Features
Interactive Graph Editor
Drag-and-drop nodes with 11 types โ Flow, Branch, Task, Bug, API, UI, Group, plus the v0.6.0 Knowledge OS entities Requirement, Decision, Experiment, and Person. Connect them by hovering and dragging the edge handle. Auto-layout with the fCOSE force-directed algorithm.
QA Impact Mode
Toggle Impact Mode to instantly highlight changed nodes and their downstream dependencies. Dimmed nodes are safe; glowing nodes need attention.
Group Nodes
Organize related nodes into collapsible groups. Drag nodes in and out. Resize groups freely. Double-click to collapse with a child count badge.
Status Tracking & Filters
Track every node as PASS / FAIL / IN_PROGRESS / BLOCKED with color-coded visuals. Filter the graph by node type or status to focus on what matters.
Node Detail Panel
Slide-out panel with full editing โ title, description (with markdown rendering), type, status, tags, connected nodes, and a complete change history audit log.
Edge Relationships
Fourteen edge types with distinct colors: the base five (depends_on, blocks, related, parent_child, triggers) plus the v0.6.0 Knowledge OS verbs (realizes, conflicts, drives, supersedes, tests, produced, owns, decided, reported). Every edge also carries a JSONB metadata bag โ supersedes records {reason}, produced records {outcome_summary}, etc. Draggable waypoints for edge routing. Click any edge to change its type or delete it.
CLI & MCP Integration
Full CLI for terminal workflows (npm install -g @thask-org/cli). 25 MCP tools for AI agent integration โ Claude Code and Cursor can query and modify your graph directly. One-step browser login (thask login), in-place upgrades (thask self-update). CLI Reference ยท MCP Guide
Per-Key Permissions & Provenance (v0.5.9+)
Every API key is classified as user_interactive, agent, or service with seven independent permission flags. Agent keys default to blocking semantic writes (description, "why" content) and node verification โ so a hallucinated description can't silently land on your graph. Every write records 6-dimension provenance (actor, channel, agent model, mutation kind, trigger, evidence) to a single audit_log table. DATABASE.md > Provenance
Suggestion Queue
Agents wanting to revise a description post to node_suggestions and a human approves before the change lands. The deciding human becomes the author of record โ the agent is credited only in audit metadata. Server-enforced: accepted decisions require a user_interactive actor regardless of permission flags.
Bulk Operations (v0.5.10+)
Three endpoints cut N round-trips down to one โ node.batch_update (up to 200), edge.batch_create / edge.batch_delete (up to 500). Atomic on permission / cycle failure; per-item skip reasons in skipped[]; HTTP 207 Multi-Status when any item skips. Saves substantial agent context (1 call vs N).
Local-First CLI Telemetry (v0.5.15+)
Every CLI invocation, MCP tool call, and HTTP response appends a single JSONL line to ~/.thask/events.jsonl โ on your machine only, no upload. Inspect with thask usage (30-day summary, p50/p95 latency, top commands), thask reflog / thask history (recent events, full-text search), or tail -f the file directly. Raw bodies are opt-in (thask telemetry config set capture_payloads true); the default captures only metadata. Tokens, URL credentials, JWT and cookies are masked at write time.
Go Dependency Scanner
Scan Go codebases to auto-generate dependency graphs. thask scan --path . parses go.mod and imports, creating nodes and edges automatically. Extensible via plugin system.
Graph Analysis
Detect dependency cycles (Tarjan DFS) and find the critical path (longest depends_on/blocks chain). Toggle Analysis Mode (Shift+A) to visualize cycles and critical path on the canvas.
External API (v1)
Versioned REST API at /api/v1/ for third-party integrations. OpenAPI 3.1 spec, interactive Scalar docs, structured error responses, and idempotency support. API Guide
Role-Based Access
Four team roles โ Owner, Admin, Member, Viewer โ with granular permissions. Per-project roles (Editor, Viewer). API key authentication for programmatic access.
Project Sharing
Share projects via link with viewer or editor access. Manage per-project members with granular roles. Public shared views support realtime collaboration. Embeddable graph views and OG image generation.
Templates
Start new projects from built-in templates: API Flow, Microservice Map, Sprint Board. One-click apply from the project creation flow.
Theme System
Light and dark mode with system detection. Persisted per user. Design system uses CSS variables throughout.
The server runs your graph database and web UI. The CLI talks to the server's API โ you can create nodes, run scans, and analyze graphs from the terminal. AI agents (Claude Code, Cursor) use the CLI's built-in MCP server.
thask login (v0.5.11+) replaces the old "make a key in Settings,
copy a 64-char string, paste it" dance. The MCP server reads the
same ~/.thask/config.json, so this single login covers Claude Code
too. For headless / SSH sessions: create a key in the web UI and
run thask config set token <key> instead.
Now Claude Code can read and modify your dependency graph โ with v0.5.9+
permission gates so agent keys can't silently land hallucinated
descriptions. See MCP Guide for details and the
official Claude Code plugin for a zero-setup
install.
Quick Start
Docker (recommended)
bash
make up # auto-generates .env with SESSION_SECRET on first run
Or manually:
bash
cp .env.example .env# Edit .env and set SESSION_SECRET (or let make generate it)
docker compose up --build
The Makefile is the source of truth โ every dev workflow has a target.
bash
make dev # one-shot: starts DB + capture worker, then backend + frontend in parallel
Or run pieces individually in separate terminals:
bash
make dev-db # PostgreSQL only (docker compose)
make dev-capture # Playwright capture worker (docker compose)
make dev-backend # Go backend (requires air: go install github.com/air-verse/air@latest)
make dev-frontend # SvelteKit frontend on :7243
If air isn't installed, run the backend directly:
bash
cd backend && cp .env.example .env && go run ./cmd/server
This configures CORS and CSRF protection automatically. BACKEND_URL does not need to change โ the frontend server proxies API requests to the backend over the internal Docker network.