Atlas / MCP servers / delorenj / Trello

TrelloBLOCK

mcp/delorenj/trello-1

A Model Context Protocol (MCP) server that provides tools for interacting with Trello boards.

Verdict
BLOCK
Grade
D
Trust score
63 /100
Exposed tools
58 35r · 19w · 4d
Transport
stdio
License
MIT
Stars
445
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/27359682-7632-4ba7-981d-7dfecadf1c4b) [](https://registry.modelcontextprotocol.io/servers/io.github.delorenj/mcp-server-trello) [](https://badge.fury.io/js/%40delorenj%2Fmcp-server-trello)

A Model Context Protocol (MCP) server that gives AI agents full access to your Trello boards — cards, lists, checklists, attachments, comments, custom fields, and workspaces — with built-in rate limiting, type safety, and workflow-level tools you won't find in a plain API wrapper, like acceptance-criteria extraction and checklist dependency queries. 57 tools, one npx install, powered by Bun.

Highlights

  • Acceptance criteria, natively: get_acceptance_criteria pulls a card's AC checklist straight into your agent's context — no competitor offers it.
  • Watch anything: watch_card and watch_list route card and list activity into your Trello notifications.
  • Full list management: create, update, reorder (update_list_position), and archive lists.
  • Board and workspace switching on the fly: no restarts, no config edits.
  • Rate limiting handled for you: respects Trello's API limits automatically (300 req/10s per key, 100 req/10s per token).
  • Bun-powered: fast startup and a 2.8-4.4x performance boost over the old Node build. npx and npm work too.

Changelog

For a detailed list of changes, see CHANGELOG.md.

Features

  • Full Trello Board Integration: Interact with cards, lists, and board activities
  • Acceptance Criteria Extraction: Pull a card's acceptance criteria checklist directly into agent context
  • **Checklist
Read from source at commit abf8efd09787OBSERVED · 2026-10-01
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-server-trello --env TRELLO_API_KEY=${TRELLO_API_KEY} --env TRELLO_TOKEN=${TRELLO_TOKEN} -- npx -y @delorenj/[email protected]
03

Exposed tools (58)

35 read · 19 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_card_to_listwrite
add_card_to_listEvalwriteEvaluates the add_card_to_list tool
add_cards_to_listwrite
add_checklist_itemwrite
add_commentwrite
add_list_to_boardwrite
archive_cardread
archive_listread
assign_member_to_cardread
attach_data_to_cardread
attach_file_to_cardread
attach_image_data_to_cardread
attach_image_to_cardread
copy_cardread
copy_checklistread
create_boardwrite
create_checklistwrite
create_labelwrite
delete_checklist_itemdestructive
delete_commentdestructive
delete_labeldestructive
download_attachmentread
find_checklist_items_by_descriptionread
get_acceptance_criteriaread
get_active_board_inforead
get_board_custom_fieldsread
get_board_labelsread
get_board_membersread
get_cardread
get_card_commentsread
get_card_historyread
get_cards_by_list_idread
get_checklist_by_nameread
get_checklist_itemsread
get_healthread
get_health_detailedread
get_health_metadataread
get_health_performanceread
get_listsread
get_my_cardsread
get_recent_activityread
list_boardsread
list_boards_in_workspaceread
list_workspacesread
move_cardwrite
perform_system_repairread
remove_member_from_carddestructive
set_active_boardwrite
set_active_workspacewrite
update_card_custom_fieldwrite
update_card_detailswrite
update_checklist_itemwrite
update_commentwrite
update_labelwrite
update_listwrite
update_list_positionwrite
watch_cardread
watch_listread
04

Trust audit

BLOCKgrade D · trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryWARN
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHPrompt injection · prompt.fetch_and_trust · CWE-94, CWE-1427
.agents/skills/.system/openai-docs/SKILL.md:24
- **Pure model-selection question only, with no prompting guidance or requested change:** directly fetch `https://developers.openai.com/api/docs/guides/latest-model.md`; do not run the resolver.
Why it matters. remote text is to be obeyed as instructions
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
.agent/skills/bmad-architecture/SKILL.md:25
When the stack is open — greenfield, or a small/beginner project that could sit on a paved path — **recommend a well-known current starter** (verify the going choice on the web first): a good one pre-
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
.agents/skills/.system/plugin-creator/SKILL.md:204
- Do not tell the user to run `codex plugin marketplace add` for the default personal-marketplace
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
.agents/skills/.system/plugin-creator/references/installing-and-updating.md:123
- Do not tell the user to run `codex plugin marketplace add` for the default personal-marketplace
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
_bmad/bmp/bmad-bmp-setup/SKILL.md:33
Ask the user for values. Show defaults in brackets. Present all values together so the user can respond once with only the values they want to change (e.g. "change language to Swahili, rest are fine")
Why it matters. asks the agent to act without the user's knowledge
MEDIUMInventory / provenance · inv.binary · CWE-1104
trello-mcp-logo.avif
trello-mcp-logo.avif
Why it matters. a compiled or binary member cannot be reviewed from source
Fix. ship source, or explain the binary in the README
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.augment/skills
.augment/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.claude/skills
.claude/skills
Why it matters. link not followed
MEDIUMInventory / provenance · inv.symlink · CWE-1104
.gemini/skills
.gemini/skills
Why it matters. link not followed
MEDIUMPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
.agent/skills/bmad-code-review/SKILL.md:3
description: 'Adversarial code review using parallel review layers and structured triage. Use when the user says "run code review" or "review this code"'
MEDIUMPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
.agent/skills/bmad-retrospective/SKILL.md:3
description: 'Post-epic review to extract lessons and assess success. Use when the user says "run a retrospective" or "lets retro the epic [epic]"'
MEDIUMPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
.agent/skills/bmad-sprint-planning/SKILL.md:3
description: 'Generate sprint status tracking from epics. Use when the user says "run sprint planning" or "generate sprint plan"'
MEDIUMPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
.agents/skills/bmad-bmp-autopilot/SKILL.md:3
description: 'Hand a target BMAD workflow to Otto for unattended execution. Otto plans, delegates to workers, answers HITL questions per a policy file, and pauses cleanly when confidence dips below fl
MEDIUMPrompt injection · prompt.conditional_escalation · CWE-94, CWE-1427
.agents/skills/bmad-code-review/SKILL.md:3
description: 'Review code changes adversarially using parallel review layers (Blind Hunter, Edge Case Hunter, Acceptance Auditor) with structured triage into actionable categories. Use when the user s
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_checklist_item, delete_comment, delete_label, remove_member_from_card
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.agents/skills/.system/.codex-system-skills.marker
.codex-system-skills.marker
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.agents/skills/mcp-server-trello-craft-doctrine/.source.yaml
.source.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.agents/skills/mcp-server-trello-growth/.source.yaml
.source.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.agents/skills/mcp-server-trello-product-doctrine/.source.yaml
.source.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.agents/skills/mcp-server-trello-release/.source.yaml
.source.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
.github/skills
.github/skills
Why it matters. link not followed
LOWInventory / provenance · inv.symlink · CWE-1104
CLAUDE.md
CLAUDE.md
Why it matters. link not followed
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
.agent/skills/bmad-brainstorming/scripts/brain.py:226
deg = int(hashlib.md5(cat.encode("utf-8")).hexdigest(), 16) % 360
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/card-list-preview.test.ts:2
import { formatCardListResponse } from '../../src/card-list-preview.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/card-list-preview.test.ts:3
import type { TrelloCard } from '../../src/types.js';

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-01 · audit v0.4.1 · source sha abf8efd09787full audit observations/trust-audit/mcp-server/delorenj__trello-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-01abf8efd09787BLOCKD63first audit
06

Questions

What is the Trello MCP server?

A Model Context Protocol (MCP) server that provides tools for interacting with Trello boards.

What tools does Trello expose?

58 in total: 35 read-only, 19 that write, and 4 that can delete or overwrite (delete_checklist_item, delete_comment, delete_label, remove_member_from_card). Every one is listed on this page with its risk.

Is Trello safe to connect to an agent?

No — not without reading the findings first. The audit graded it D (63/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Trello need?

It reads GH_TOKEN, GITHUB_TOKEN, LINEAR_API_KEY, OPENAI_API_KEY, PLANE_33GOD_API_KEY, TRELLO_API_KEY and TRELLO_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Trello run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @delorenj/mcp-server-trello at 1.8.0.

How current is this page?

The grade is for one exact copy of the source (abf8efd09787), read on 2026-10-01. The repository is watched and re-audited when it changes.

Advertisement