TestRail MCP Server (TenBarrel6/testrail-mcp) is an MCP server listed on the M8ven Trust Index. It scores 58 out of 100, grade D. It declares 77 tools. No publisher has claimed this listing.
Enables AI assistants to interact directly with TestRail instances for managing test projects, suites, cases, runs, results, plans, milestones, and attachments through the TestRail API with secure authentication.
Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.
How we verified
Verified is a snapshot. Live keeps it current, and builds your track record.
⚡ Connect GitHub → continuous verification on every pushwhy connect →Who stands behind it
TenBarrel6
Source: Glama
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →
Install from
The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.
These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.
get_projectsGet all TestRail projects
get_projectGet a specific project by ID
get_suitesGet all test suites for a project
get_suiteGet a specific test suite by ID
add_suiteCreate a new test suite
update_suiteUpdate an existing test suite
get_sectionsGet all sections for a project/suite
get_sectionGet a specific section by ID
add_sectionCreate a new section
update_sectionUpdate an existing section
delete_sectionDelete a section
move_sectionMove a section to another parent or position
get_casesGet test cases for a project/suite
get_caseGet a specific test case by ID
add_caseCreate a new test case
update_caseUpdate an existing test case
delete_caseDelete a test case
get_case_typesGet all available test case types
get_case_fieldsGet all available test case fields
get_history_for_caseGet the edit history for a test case
copy_cases_to_sectionCopy test cases to another section
move_cases_to_sectionMove test cases to another section
delete_casesDelete multiple test cases
get_runsGet test runs for a project
get_runGet a specific test run by ID
add_runCreate a new test run
update_runUpdate an existing test run
close_runClose a test run
delete_runDelete a test run
get_testsGet tests for a test run
get_testGet a specific test by ID
get_resultsGet results for a test
get_results_for_caseGet results for a test case in a run
get_results_for_runGet results for a test run
add_resultAdd a test result
add_result_for_caseAdd a test result for a specific case in a run
add_results_for_casesAdd multiple test results for cases in a run
add_resultsAdd multiple test results by test IDs
get_plansGet test plans for a project
get_planGet a specific test plan by ID
add_planCreate a new test plan
add_plan_entryAdd test runs to a test plan
add_run_to_plan_entryAdd a test run to an existing plan entry
update_planUpdate an existing test plan
update_plan_entryUpdate a test plan entry
update_run_in_plan_entryUpdate a test run inside a plan entry
close_planClose a test plan
delete_planDelete a test plan
delete_plan_entryDelete a test plan entry
delete_run_from_plan_entryDelete a test run from a plan entry
get_milestonesGet milestones for a project
get_milestoneGet a specific milestone by ID
add_milestoneCreate a new milestone
update_milestoneUpdate an existing milestone
delete_milestoneDelete a milestone
get_userGet a user by ID
get_current_userGet the current authenticated user
get_user_by_emailGet a user by email address
get_usersGet all users (optionally filtered by project)
get_statusesGet all available test result statuses
get_case_statusesGet all available test case statuses (Enterprise)
get_prioritiesGet all available test case priorities
get_templatesGet all templates for a project
get_configsGet all configurations for a project
get_result_fieldsGet all available result custom fields
add_attachment_to_caseAdd an attachment to a test case
add_attachment_to_resultAdd an attachment to a test result
add_attachment_to_runAdd an attachment to a test run
add_attachment_to_planAdd an attachment to a test plan
add_attachment_to_plan_entryAdd an attachment to a test plan entry
get_attachmentGet/download an attachment by ID
get_attachments_for_caseGet all attachments for a test case
get_attachments_for_testGet all attachments for a test
get_attachments_for_runGet all attachments for a test run
get_attachments_for_planGet all attachments for a test plan
get_attachments_for_plan_entryGet all attachments for a test plan entry
delete_attachmentDelete an attachment
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig
Axios: Header Injection via Prototype Pollution
TESTRAIL_API_KEYshould be a valid API key (not your password)TESTRAIL_URLshould include the protocol (https://)TESTRAIL_USERNAMEshould be your email addressTool annotations
No tools have read-only/destructive annotations
Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.
All four hints declared on every tool
77/77 tools missing one or more hints — get_projects (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_project (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); get_suites (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +74 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.
For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.
Tests exist
No test files found
Add tests that exercise each declared tool.
Production dependencies are patched
0 critical, 12 high severity in production deps — @modelcontextprotocol/sdk@0.4.0 (high), axios@1.13.2 (high)
Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.
Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.
[](https://m8ven.ai/mcp/tenbarrel6/testrail-mcp)?variant=verified from the URL.Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.
https://m8ven.ai/api/mcp/tool-check