taskmaster

A reference for Taskmaster, a task-management tool that stores and updates development tasks through MCP integrations or its command-line interface.

In plain words
What is it for?
It helps create, expand, update, analyze, and organize tasks across separate features, branches, or experiments.
Why use it?
It explains which interface to use and how to work with AI-assisted task operations, tagged task lists, and fallback commands.

Cursor rule for Cursor

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/compozy/gograph/taskmaster
Clone the repo
git clone --depth 1 https://github.com/compozy/gograph

Made for: Cursor.

Per session 12 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 10,992 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 1 finding. Scan, not verified.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00012 $0.10992
Opus 5 $0.00006 $0.05496
Sonnet 5 $0.00002 $0.02198
Haiku 4.5 $0.00001 $0.01099

Measured yesterday against content hash eedd7b8a6f4b, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

taskmaster scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads MCP configurationmediumAgent snooping

mcp.json carries server URLs and auth tokens; reading it lets a mod discover and abuse other integrations.

**Set API keys** in your **`.env`** file in the project root (for CLI use) or within the `env` section of your **`.cursor/mcp.json`** file (for MCP/Cursor integration). All other settings (model choice, max tokens, tempe
Origin

This is a copy

100% identical to taskmaster — 18 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.cursor/rules/taskmaster.mdc · 558 lines

How it starts

The opening of the file, as written. The whole thing — 558 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Taskmaster Tool & Command Reference

This document provides a detailed reference for interacting with Taskmaster, covering both the recommended MCP tools, suitable for integrations like Cursor, and the corresponding task-master CLI commands, designed for direct user interaction or fallback.

Note: For interacting with Taskmaster programmatically or via integrated tools, using the MCP tools is strongly recommended due to better performance, structured data, and error handling. The CLI commands serve as a user-friendly alternative and fallback.

Important: Several MCP tools involve AI processing... The AI-powered tools include parse_prd, analyze_project_complexity, update_subtask, update_task, update, expand_all, expand_task, and add_task.

🏷️ Tagged Task Lists System: Task Master now supports tagged task lists for multi-context task management. This allows you to maintain separate, isolated lists of tasks for different features, branches, or experiments. Existing projects are seamlessly migrated to use a default "master" tag. Most commands now support a --tag <name> flag to specify which context to operate on. If omitted, commands use the currently active tag.


Initialization & Setup

1. Initialize Project (init)

  • MCP Tool: initialize_project
  • CLI Command: task-master init [options]
  • Description: Set up the basic Taskmaster file structure and configuration in the current directory for a new project.
  • Key CLI Options:
    • --name <name>: Set the name for your project in Taskmaster's configuration.
    • --description <text>: Provide a brief description for your project.
    • --version <version>: Set the initial version for your project, e.g., '0.1.0'.
    • -y, --yes: Initialize Taskmaster quickly using default settings without interactive prompts.
  • Usage: Run this once at the beginning of a new project.
  • MCP Variant Description: Set up the basic Taskmaster file structure and configuration in the current directory for a new project by running the 'task-master init' command.
  • Key MCP Parameters/Options:
    • projectName: Set the name for your project. (CLI: --name <name>)
    • projectDescription: Provide a brief description for your project. (CLI: --description <text>)
    • projectVersion: Set the initial version for your project, e.g., '0.1.0'. (CLI: --version <version>)
    • authorName: Author name. (CLI: --author <author>)
    • skipInstall: Skip installing dependencies. Default is false. (CLI: --skip-install)
    • addAliases: Add shell aliases tm and taskmaster. Default is false. (CLI: --aliases)
    • yes: Skip prompts and use defaults/provided arguments. Default is false. (CLI: -y, --yes)
  • Usage: Run this once at the beginning of a new project, typically via an integrated tool like Cursor. Operates on the current working directory of the MCP server.
  • Important: Once complete, you MUST parse a prd in order to generate tasks. There will be no tasks files until then. The next step after initializing should be to create a PRD using the example PRD in .taskmaster/templates/example_prd.txt.
  • Tagging: Use the --tag option to parse the PRD into a specific, non-default tag context. If the tag doesn't exist, it will be created automatically. Example: task-master parse-prd spec.txt --tag=new-feature.

Read the full file on GitHub · 558 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 558 lines · 12 tokens per session scan B eedd7b8a6f4b

Subscribe to this mod's changes

taskmaster is a cursor rule published in the GitHub repository compozy/gograph (9 stars, last pushed 1y ago), licensed MIT. It adds 12 tokens to every session and 10,992 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it B with 1 finding (reads mcp configuration). It is 100% identical to taskmaster, differing in 18 lines, and is treated as a copy.