LIQA (thejanaloit/LIQA) is an MCP server listed on the M8ven Trust Index. It scores 73 out of 100, grade C. It declares 114 tools. No publisher has claimed this listing.

C
Caution
73/100

LIQA

LIQA — Live Intelligent QA. Sigiri Manual steps via headed Xray UI RPA (no API keys). 2QA + Workers + agency mesh.

Caution. Specific findings reduced this grade. They are listed on the page. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

thejanaloit

Source: github_repo_search

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
⚠️
Tool descriptions don’t match what handlers do
1 tool describes read intent but its handler mutates — liqa_testcase_sufficiency (line 410: path.write_text(json.dumps(payload, indent=2), encoding="utf-8"))
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
Open source with a license and README
Anyone can audit the code, the license is declared, and the publisher documents what it does.
🔐
You'll be asked for 8 credentials: LIQA_CONTROL_TOKEN, XRAY_CLIENT_SECRET, LIQA_CSRF_SECRET, LIQA_SIGNING_SECRET, LIQA_WORKER_TOKEN, CURSOR_API_KEY, AZURE_OPENAI_KEY, ATLASSIAN_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// tools this server exposes107 tools

These names and descriptions are the publisher's own, read from the source code. We print them as written. Our assessment is the findings above, not this list.

liqa_boot

Boot Theja Manual QA Company (merged FINAL): workspace, persona, next phase.

liqa_laws

Return global ManualQA laws + ISTQB phase map + engineer absolute laws.

liqa_engineer_persona

Full Manual QA Engineer identity: YouTube analogy + absolute laws + Book1 columns.

liqa_status

ISTQB phase checklist + monitor + next action. Call every turn.

liqa_todo_list

Numbered company TODO list (ISTQB phases) — alias of status for operators.

liqa_flow_chart

Return ISTQB mermaid/text flow chart and write agents/FLOW-CHART.md.

liqa_complete_phase

Mark an ISTQB phase done (1..7). Prior phases must already be done.

liqa_set_notes

Attach notes / mark phase in_progress.

liqa_heartbeat

Heartbeat after meaningful work. Pass blocker text to freeze live phases; empty to clear.

liqa_request_credentials

Ask for 2–3 credentials (Ask mode). Secrets go in secrets/tmp-creds.json only.

liqa_credentials_status

Report whether credentials/access are enough. Omit enough to only read status.

liqa_announce_planning_done

Tell the user planning intake succeeded (after phase 1 + Jira harvest complete).

liqa_jira_harvest_checklist

Mandatory Atlassian pull list before headed map (attachments + epic/feature links).

liqa_jira_harvest_status

Check whether full Jira harvest for KEY is complete (gate before headed map).

liqa_jira_harvest_record

Record Jira harvest progress after Atlassian pulls. sources/attachment_names = comma-separated.

liqa_save_assigned_task

Save assigned Jira task as plain-English MD under assignedTasks/<KEY>/.

liqa_save_user_story

Save user story under UserStories/<KEY>/.

liqa_save_existing_testcase

Save existing Xray/is-tested-by reference (read-only) under ExistingTestCases/<KEY>/.

liqa_save_map_node

Save experience-map node under map/<KEY>/ (no Pass/Fail).

liqa_save_new_testcase

Save NEW test case under NewTestCases/<KEY>/. Never edit existing Xray.

liqa_save_knowledge

Harvest Jira tone / format notes into knowledgeBase/.

liqa_testcase_sufficiency

Record whether new test count is enough for a story (show count + enough yes/no).

liqa_role_list

List in-process Manual QA roles (intake, mapper, designer, executor, …).

liqa_role_start

Start a role; writes workspace/agents/role-<name>.json.

liqa_role_status

Status for one role or all roles (from workspace/agents/*.json).

liqa_role_dispatch

Dispatch a role with an instruction; returns role contract for the agent to obey.

liqa_book1_sample

Create Book1 sample workbook scaffold for a story.

liqa_book1_append_row

Append one full-English Book1 row. Embed screenshot when path exists. Bugs use red Issue fill.

liqa_book1_validate

Validate Book1 against SHARE gold contract (100% screenshots + full English).

liqa_list_outputs

List Book1 / report outputs in workspace.

liqa_file_bug_draft

Write bugs/<KEY>/ draft MD+JSON. Agent uploads to Jira via Atlassian MCP (not hardcoded API).

liqa_honesty_start

Start an honesty case (20 approaches before REAL_BUG; 3 for obvious classes).

liqa_honesty_attempt

Record one headed approach with proof path.

liqa_honesty_verdict

Set PASS | REAL_BUG | BLOCKED | N/A — enforced by honesty contract.

liqa_device_status

Windows device / OCR / monitor status.

liqa_capture

Full-desktop screenshot. OCR off by default (fast). Optional monitor_index for multi-monitor.

liqa_click

Visible mouse click at screen coordinates (Eyes first — never guess).

liqa_click_text

OCR find text then click center. Requires Tesseract.

liqa_move

Bezier mouse move (visible).

liqa_type

Type text via pyautogui (visible delay). Never pass passwords into chat — use Human Gate for secrets.

liqa_hotkey

Press hotkey combo via pyautogui, e.g. 'ctrl+s' or 'alt+tab'.

liqa_wait_frame

Wait until desktop pixels change (hash-only, fast).

liqa_list_windows

List top-level Windows titles.

liqa_focus_window

Focus a window by title substring.

liqa_human_gate

Pause for OTP / MFA / CAPTCHA — never invent codes.

liqa_learn_cycle

ISTQB completion learn cycle + speed playbook uplift.

liqa_list_skills

List skill packs under repo skills/ (SBTM, defect-reporting, jira-tone, book1-english, …).

liqa_orchestrator_assign

Company orchestrator: assign a workstream to a specialist role and log it.

liqa_company_status

Full company snapshot: engineer + ISTQB phases + roles + embedded agency specialists.

liqa_fresh_task

Start a task clean: ignore prior memories for this KEY.

liqa_self_assign

Assign yourself (company Manual QA Engineer) and dispatch all core roles.

liqa_await_otp_field

Poll OCR/clipboard for OTP digits — never invent codes; human types or copies.

liqa_ack_gate

Create ACK so an active Human Gate (manual_ack) resumes.

liqa_browser_open

Open entry URL once in headed default browser. After: mouse-click navigation only.

liqa_sbtm_charter

Create SBTM exploratory charter under map/<KEY>/sbtm/ (no Pass/Fail).

liqa_revalidate_cycle

Completion honesty revalidate cycle 1|2|3 — need 3 honest cycles to close.

liqa_seed_format_refs

Seed knowledgeBase harvest format refs (SSP/PF gold URLs) — then harvest live tone.

liqa_test_case_template

Emit Sigiri PF-59194 Manual test template (Action|Data|Expected Result).

liqa_sigiri_laws

Locked Sigiri/TestCrafters Xray Manual step laws (PF-59194 gold).

liqa_xray_gold_steps

Load PF-59194 gold Manual steps CSV (Action|Data|Expected Result).

liqa_xray_split_paths

Split user story into path parts before writing Manual steps (owner law).

liqa_xray_validate_steps

Guard: validate Manual steps are Sigiri-simple Action|Data|Expected Result. Blocks upload on fail.

liqa_xray_build_manual_test

Build CSV+MD Manual pack after guard pass — ready for Xray Import / ADD NEW Test.

liqa_xray_validate_title

Guard: PF titles must follow Sigiri pipe taxonomy (not bracket FP titles).

liqa_xray_credentials_status

Check whether Xray Cloud API keys are configured for Manual-step import.

liqa_xray_set_credentials

Save Xray API Client Id/Secret to secrets/xray.env (gitignored). Never commit.

liqa_xray_import_steps

Push Sigiri Manual steps (Action|Data|Expected Result JSON) into an existing Xray Test.

liqa_xray_import_csv

Import a Sigiri CSV (Action,Data,Expected Result) into Xray Manual steps on issue_key.

liqa_xray_import_pack

Import NewTestCases/<story>/sigiri-manual/<pack>/<pack>-steps.csv into Xray Test.

liqa_xray_import_registry

Import every pack in jira-created.json (default PF-58380 Sigiri registry) into Xray.

liqa_xray_ui_method

Return the locked Sigiri/Xray UI CSV import method (Action*|Data|Expected Result wizard).

liqa_xray_ui_import_csv

RPA: open Jira Test in Chrome and Import Manual steps CSV (no Xray API keys needed).

liqa_xray_ui_import_pack

RPA: import sigiri-manual/<pack> CSV into Xray Test via headed UI.

liqa_xray_ui_import_registry

RPA end-of-run: import every pack in jira-created.json via headed Chrome (no API keys).

liqa_xray_upload_after_run

End-of-run hook: try Xray API if keys exist, else UI RPA Import/Add Step.

liqa_xray_ui_ensure_login

One-time: open Chrome profile and wait while you log into Jira (OTP yourself).

liqa_xray_end_of_run_upload

Upload all Sigiri packs from jira-created.json via headed UI RPA (auto on phase 7 / learn).

liqa_evaluate_all

Re-evaluate ISTQB phases 1..7 for regressions / monitor blockers.

liqa_stop_the_line

Freeze live phases with a blocker (quality stop). Clear via liqa_heartbeat() empty.

liqa_proof_crop

Crop proof PNG to bbox with optional red outline for Book1 + Jira attach.

liqa_list_monitors

List monitors for multi-monitor capture targeting.

liqa_recursive_step

One Eyes→Hands recursive step: capture + actionable summary (brain = host LLM).

liqa_calibrate_viewport

Save browser viewport→screen calibration for accurate clicks.

liqa_viewport_click

Click using calibrated viewport coordinates.

liqa_persona

Alias of liqa_engineer_persona — company + engineer identity.

liqa_list_roles

Alias of liqa_role_list.

liqa_press

Press a single key (enter, tab, esc, …).

liqa_hotkey_chord

Hotkey from comma-separated string, e.g. 'ctrl,v' — also accepts 'ctrl+v' via liqa_hotkey.

liqa_device_loop

One Eyes-Brain-Hands loop step (capture + actionable summary).

liqa_agency_list

List agency-agents specialists available to LIQA orchestrator (250+).

liqa_agency_dispatch

Assign an agency specialist workstream under LIQA orchestrator.

liqa_mesh_status

Agency mesh assignment snapshot.

liqa_agency_train_status

Status of QA training overlays for all agency specialists.

liqa_agency_trained_prompt

Load the LIQA Manual-QA trained overlay for one specialist.

liqa_learn_speed

Suggest speed-up tips from prior LIQA rounds (call at planning).

liqa_learn_record

Record a learning round to uplift future QA speed.

liqa_resource_map

Map connected product sources LIQA absorbs (ManualQA, QAFusionX, agency, worker).

liqa_product_status

Final product readiness snapshot for LIQA MCP.

liqa_lolc_status

LOLC FusionX overlay pack status (separate from Perfect-100).

liqa_lolc_laws

How LOLC QA engineers write on lolcgroupdev project PF.

7 further tools are not listed here. The complete surface is in the source.

// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
configMQA_BUILD
configLIQA_CONTROL_HOST
configLIQA_CONTROL_PORT
🔐 secretLIQA_CONTROL_TOKEN
configLIQA_CONTROL_DATA
configLIQA_CORS
configLIQA_TELEMETRY
configLIQA_AGENCY_HOME
configMANUAL_QA_HOME
configQAFUSIONX_HOME
configLIQA_HOME
configLIQA_CAPTURE_DIR
configLIQA_WORKSPACE
configLIQA_VAULT
configXRAY_CLIENT_ID
🔐 secretXRAY_CLIENT_SECRET
configXRAY_BASE_URL
configLIQA_CHROME_CDP
🔐 secretLIQA_CSRF_SECRET
configLIQA_WORKER_SEATS
configLIQA_OIDC_ISSUER
configLIQA_OIDC_CLIENT
🔐 secretLIQA_SIGNING_SECRET
configLIQA_WORKER_HOST
configLIQA_WORKER_PORT
🔐 secretLIQA_WORKER_TOKEN
configLIQA_WORKER_JOBS
configLIQA_CONTROL_URL
configCURSOR_API_BASE
🔐 secretCURSOR_API_KEY
configLIQA_OLLAMA
configLIQA_BRAIN_MODEL
configLIQA_BRAIN_MODE
configLIQA_VL_MODEL
🔐 secretAZURE_OPENAI_KEY
configLIQA_ALLOW_CLOUD_BRAIN
configAZURE_OPENAI_ENDPOINT
configLIQA_CAPTURE_ROOT
configLIQA_CAPTURE_MAX_MB
configLIQA_HEADED
configQAFUSIONX_HEADED
configHUMANIZE_HEADLESS
configSESSIONNAME
🔐 secretATLASSIAN_TOKEN
configLIQA_DEBUG_URL
configLIQA_PROFILES
// quality suggestions

Tool annotations

No tools have read-only/destructive annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

114/114 tools missing one or more hints — liqa_boot (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); liqa_laws (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint); liqa_engineer_persona (missing: readOnlyHint, destructiveHint, idempotentHint, openWorldHint), +111 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Descriptions match behaviour

1 tool describes read intent but its handler mutates — liqa_testcase_sufficiency (line 410: path.write_text(json.dumps(payload, indent=2), encoding="utf-8"))

Rename the tool, rewrite the description, or move the side-effect into a separate clearly-named tool.

Tool test coverage

Only 7/114 tools referenced in tests (6%)

Write tests that reference each tool by name so every tool has at least one test.

Tool description accuracy

liqa_testcase_sufficiency: description implies read-only but handler writes/deletes/executes

Update tool descriptions to accurately reflect all capabilities — especially write, delete, or execute operations.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/thejanaloit/liqa?variant=verified)](https://m8ven.ai/mcp/thejanaloit/liqa)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: a5ca30d0e25c060250e8bf356c8411656fcc9476
code hash: b3514e5674292d49da18f952529f68eafcab22e8c2645a10a6cb21f2d8127eda
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client