TrelloBLOCK
A Model Context Protocol (MCP) server that provides tools for interacting with Trello boards.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mseep.ai/app/27359682-7632-4ba7-981d-7dfecadf1c4b) [](https://registry.modelcontextprotocol.io/servers/io.github.delorenj/mcp-server-trello) [](https://badge.fury.io/js/%40delorenj%2Fmcp-server-trello)
A Model Context Protocol (MCP) server that gives AI agents full access to your Trello boards — cards, lists, checklists, attachments, comments, custom fields, and workspaces — with built-in rate limiting, type safety, and workflow-level tools you won't find in a plain API wrapper, like acceptance-criteria extraction and checklist dependency queries. 57 tools, one npx install, powered by Bun.
Highlights
- Acceptance criteria, natively:
get_acceptance_criteriapulls a card's AC checklist straight into your agent's context — no competitor offers it. - Watch anything:
watch_cardandwatch_listroute card and list activity into your Trello notifications. - Full list management: create, update, reorder (
update_list_position), and archive lists. - Board and workspace switching on the fly: no restarts, no config edits.
- Rate limiting handled for you: respects Trello's API limits automatically (300 req/10s per key, 100 req/10s per token).
- Bun-powered: fast startup and a 2.8-4.4x performance boost over the old Node build.
npxandnpmwork too.
Changelog
For a detailed list of changes, see CHANGELOG.md.
Features
- Full Trello Board Integration: Interact with cards, lists, and board activities
- Acceptance Criteria Extraction: Pull a card's acceptance criteria checklist directly into agent context
- **Checklist
abf8efd09787OBSERVED · 2026-10-01Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-server-trello --env TRELLO_API_KEY=${TRELLO_API_KEY} --env TRELLO_TOKEN=${TRELLO_TOKEN} -- npx -y @delorenj/[email protected]Exposed tools (58)
35 read · 19 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_card_to_list | write | |
add_card_to_listEval | write | Evaluates the add_card_to_list tool |
add_cards_to_list | write | |
add_checklist_item | write | |
add_comment | write | |
add_list_to_board | write | |
archive_card | read | |
archive_list | read | |
assign_member_to_card | read | |
attach_data_to_card | read | |
attach_file_to_card | read | |
attach_image_data_to_card | read | |
attach_image_to_card | read | |
copy_card | read | |
copy_checklist | read | |
create_board | write | |
create_checklist | write | |
create_label | write | |
delete_checklist_item | destructive | |
delete_comment | destructive | |
delete_label | destructive | |
download_attachment | read | |
find_checklist_items_by_description | read | |
get_acceptance_criteria | read | |
get_active_board_info | read | |
get_board_custom_fields | read | |
get_board_labels | read | |
get_board_members | read | |
get_card | read | |
get_card_comments | read | |
get_card_history | read | |
get_cards_by_list_id | read | |
get_checklist_by_name | read | |
get_checklist_items | read | |
get_health | read | |
get_health_detailed | read | |
get_health_metadata | read | |
get_health_performance | read | |
get_lists | read | |
get_my_cards | read | |
get_recent_activity | read | |
list_boards | read | |
list_boards_in_workspace | read | |
list_workspaces | read | |
move_card | write | |
perform_system_repair | read | |
remove_member_from_card | destructive | |
set_active_board | write | |
set_active_workspace | write | |
update_card_custom_field | write | |
update_card_details | write | |
update_checklist_item | write | |
update_comment | write | |
update_label | write | |
update_list | write | |
update_list_position | write | |
watch_card | read | |
watch_list | read |
Trust audit
BLOCKgrade D · trust 63/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (9 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (25)
- **Pure model-selection question only, with no prompting guidance or requested change:** directly fetch `https://developers.openai.com/api/docs/guides/latest-model.md`; do not run the resolver.
When the stack is open — greenfield, or a small/beginner project that could sit on a paved path — **recommend a well-known current starter** (verify the going choice on the web first): a good one pre-
- Do not tell the user to run `codex plugin marketplace add` for the default personal-marketplace
- Do not tell the user to run `codex plugin marketplace add` for the default personal-marketplace
Ask the user for values. Show defaults in brackets. Present all values together so the user can respond once with only the values they want to change (e.g. "change language to Swahili, rest are fine")
trello-mcp-logo.avif
.augment/skills
.claude/skills
.gemini/skills
description: 'Adversarial code review using parallel review layers and structured triage. Use when the user says "run code review" or "review this code"'
description: 'Post-epic review to extract lessons and assess success. Use when the user says "run a retrospective" or "lets retro the epic [epic]"'
description: 'Generate sprint status tracking from epics. Use when the user says "run sprint planning" or "generate sprint plan"'
description: 'Hand a target BMAD workflow to Otto for unattended execution. Otto plans, delegates to workers, answers HITL questions per a policy file, and pauses cleanly when confidence dips below fl
description: 'Review code changes adversarially using parallel review layers (Blind Hunter, Edge Case Hunter, Acceptance Auditor) with structured triage into actionable categories. Use when the user s
delete_checklist_item, delete_comment, delete_label, remove_member_from_card
.codex-system-skills.marker
.source.yaml
.source.yaml
.source.yaml
.source.yaml
.github/skills
CLAUDE.md
deg = int(hashlib.md5(cat.encode("utf-8")).hexdigest(), 16) % 360import { formatCardListResponse } from '../../src/card-list-preview.js';import type { TrelloCard } from '../../src/types.js';Gates applied: instruction_override, no_behavioural_pass.
abf8efd09787full audit observations/trust-audit/mcp-server/delorenj__trello-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-01 | abf8efd09787 | BLOCK | D | 63 | first audit |
Questions
What is the Trello MCP server?
A Model Context Protocol (MCP) server that provides tools for interacting with Trello boards.
What tools does Trello expose?
58 in total: 35 read-only, 19 that write, and 4 that can delete or overwrite (delete_checklist_item, delete_comment, delete_label, remove_member_from_card). Every one is listed on this page with its risk.
Is Trello safe to connect to an agent?
No — not without reading the findings first. The audit graded it D (63/100) and found 5 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Trello need?
It reads GH_TOKEN, GITHUB_TOKEN, LINEAR_API_KEY, OPENAI_API_KEY, PLANE_33GOD_API_KEY, TRELLO_API_KEY and TRELLO_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Trello run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @delorenj/mcp-server-trello at 1.8.0.
How current is this page?
The grade is for one exact copy of the source (abf8efd09787), read on 2026-10-01. The repository is watched and re-audited when it changes.