testrail-mcp (samuelvinay91/testrail-mcp) is an MCP server listed on the M8ven Trust Index. It scores 49 out of 100, grade D. It declares 64 tools. No publisher has claimed this listing.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

samuelvinay91

Source: ModelScope

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: TESTRAIL_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 15 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 1 credential: TESTRAIL_API_KEY
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes64 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

connect_testrail

Connect to TestRail instance with credentials

test_connection

Test TestRail connection and validate credentials

get_projects

Get all TestRail projects

get_project

Get specific TestRail project by ID

create_project

Create new TestRail project

get_suites

Get all test suites for a project

create_suite

Create new test suite

get_sections

Get all sections for a project/suite

create_section

Create new section

get_cases

Get test cases for a project/suite

create_case

Create new test case

update_case

Update existing test case

delete_case

Delete test case

get_runs

Get test runs for a project

create_run

Create new test run

update_run

Update test run

close_run

Close test run

delete_run

Delete test run

get_tests

Get tests in a run

add_result

Add test result

add_bulk_results

Add multiple test results

get_results

Get test results

get_users

Get TestRail users

get_statuses

Get available test statuses

get_priorities

Get available test case priorities

get_case_types

Get available test case types

generate_report

Generate comprehensive test report

search

Search across TestRail entities

create_advanced_project

Create a comprehensive project with templates and initial structure

analyze_project_structure

Analyze project structure and provide health recommendations

bulk_manage_suites

Perform bulk operations on test suites with validation

create_advanced_suite

Create a comprehensive suite with templates and structure

generate_project_dashboard

Generate comprehensive project dashboard with metrics and trends

generate_execution_report

Generate detailed test execution report

analyze_case_metrics

Analyze test case metrics and health

generate_coverage_report

Generate comprehensive test coverage report

autospectra_sync

Synchronize AutoSpectra test results with TestRail

add_plan_entry

Add entry to test plan

update_plan_entry

Update test plan entry

delete_plan_entry

Delete test plan entry

get_plan_entries

Get test plan entries

close_plan_entry

Close test plan entry

reopen_plan

Reopen test plan

get_milestone

Get specific milestone by ID

create_milestone

Create new milestone (enhanced)

update_milestone

Update milestone (enhanced)

delete_milestone

Delete milestone (enhanced)

get_milestone_dependencies

Get milestone dependencies

update_milestone_dependencies

Update milestone dependencies

get_templates

Get case templates for project

get_configurations

Get configurations for project

get_config_groups

Get configuration groups for project

update_project

Update existing project

delete_project

Delete project

get_project_permissions

Get project permissions

update_project_permissions

Update project permissions

export_cases

Export test cases

export_runs

Export test runs

get_reports

Get detailed reports

add_attachment

Add attachment to entity

get_attachments

Get attachments for entity

delete_attachment

Delete attachment

create_user

Create new user

update_user

Update existing user

// known CVEs in dependencies15 high5 medium12 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

high@modelcontextprotocol/sdk@1.17.4GHSA-345p-7cg4-v4c7

@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse

high@modelcontextprotocol/sdk@1.17.4GHSA-8r9q-7v3j-jr4g

Anthropic's MCP TypeScript SDK has a ReDoS vulnerability

high@modelcontextprotocol/sdk@1.17.4GHSA-w48q-cv73-mx4w

Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default

highaxios@1.11.0GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.11.0GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configAUTOSPECTRA_OUTPUT_PATH
configCACHE_TTL
configDEFAULT_PROJECT_ID
configDEFAULT_SUITE_ID
configRATE_LIMIT_REQUESTS_PER_MINUTE
🔐 secretTESTRAIL_API_KEY
configTESTRAIL_BASE_URL
configTESTRAIL_URL
configTESTRAIL_USERNAME
configTEST_ENVIRONMENT
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

64/64 tools missing one or more hints — connect_testrail (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); test_connection (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_projects (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +61 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool test coverage

26/64 tools referenced in tests (41%)

Write tests that reference each tool by name so every tool has at least one test.

Secrets not logged

2 secret values sent to log

Redact or omit secret values from log output.

Production dependencies are patched

0 critical, 15 high severity in production deps — @modelcontextprotocol/sdk@1.17.4 (high), @modelcontextprotocol/sdk@1.17.4 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/skopaq-ai/testrail-mcp?variant=verified)](https://m8ven.ai/mcp/skopaq-ai/testrail-mcp)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: ff98ad88e5aba92ffbda7194757ccb6a29236df1
code hash: 8c7182c8b8c93d7c7d1c9869cb038e479e080c3ba8e0af201e8f71ce566fa497
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client