by markrai
Self-hosted project management • Customizable boards • Cross-project workload and flow analytics • Calendar/Agenda • Sticky-note wall • Imports/Backups • Email notifications • MCP/Agent automation
# Add to your Claude Code skills
git clone https://github.com/markrai/scrumboyLast scanned: 5/30/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-05-30T14:59:57.136Z",
"npmAuditRan": true,
"pipAuditRan": true
}See how scrumboy compares with popular alternatives.
scrumboy is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by markrai. Self-hosted project management • Customizable boards • Cross-project workload and flow analytics • Calendar/Agenda • Sticky-note wall • Imports/Backups • Email notifications • MCP/Agent automation. It has 444 GitHub stars.
Yes. scrumboy passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/markrai/scrumboy" and add it to your Claude Code skills directory (see the Installation section above).
scrumboy is primarily written in Go. It is open-source under markrai on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh scrumboy against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.

Runs in seconds. No setup required.
No .env file, TLS certificates, or encryption key are required to start the app.
Scrumboy creates runtime data under ./data by default. The default SQLite database is ./data/app.db, and SQLite may also create app.db-wal and app.db-shm while the server is running.
Pull ghcr.io/markrai/scrumboy:latest (Docker selects the published architecture for your host):
docker run -d \
--name scrumboy \
-p 127.0.0.1:8080:8080 \
-v scrumboy-data:/data \
ghcr.io/markrai/scrumboy:latest
The mounted /data volume preserves Scrumboy data across container recreation. Open http://localhost:8080. For Compose using the published image, persistence, backup, and configuration details, see docs/docker.md.
To build from a local clone instead of pulling the published image:
docker compose up --build
The repository's docker-compose.yml uses build: . and maps ./data to /data.
Open http://localhost:8080.
go run ./cmd/scrumboy
Open http://localhost:8080.
Windows users can download the windows-amd64 executable from GitHub Releases. Run it from a dedicated writable folder (for example %USERPROFILE%\Scrumboy); it starts a local Scrumboy server at http://localhost:8080. For exact artifact filenames, checksum and provenance verification, runtime-data location, and other release-install details, see docs/install-from-releases.md.
macOS users can download Apple Silicon or Intel builds from GitHub Releases. These binaries require macOS 12 Monterey or later. Extract and run ./scrumboy from a dedicated writable folder; it starts a local Scrumboy server at http://localhost:8080. Current macOS release binaries are not Apple-signed or notarized. For exact artifact filenames, checksum and provenance verification, runtime-data location, Gatekeeper/quarantine troubleshooting, and other release-install details, see docs/install-from-releases.md.
Scrumboy includes a native Android client, implemented with Capacitor, under mobile/capacitor. It connects to a running Scrumboy server; it does not replace or start the server. Build it from source. Release builds require HTTPS to that server. Prerequisites, web-payload packaging, Gradle commands, device connection, and optional signing are in docs/android.md.
todo.assigned). For your own automations, not in-app or browser notifications. See Integrations.doneAt, tags, links, sprint, priority and assignment are preserved, so metrics and sprint history are unaffected. Every board reader can browse the cursor-paginated Archive and inspect archived stories in a clearly marked read-only detail view; maintainers (and temporary-board capability holders) can restore or hard-delete them. Archived stories drop out of board, search and dashboard reads while still counting for integrity checks. The same single and atomic batch (1-500) operations are available over REST and MCP. Nothing is archived automatically. See API.md and docs/mcp.md.SCRUMBOY_ENCRYPTION_KEY is set.SCRUMBOY_ENCRYPTION_KEY + SCRUMBOY_PUBLIC_BASE_URL): see docs/smtp.md.audit_events table; todo/member/project/link actions logged (see docs/audit-trail.md).DATA_DIR disaster-recovery backup (uploaded wallpapers and audit_events are omitted); see docs/diagrams/scrumboy_deployment_ops.md.SCRUMBOY_ENCRYPTION_KEY.SCRUMBOY_MODE=full, default): Auth can be enabled. First user via bootstrap; then login/session. Backup/export