Atlas / MCP servers / desplega-ai / QA-Use

QA-UseBLOCK

mcp/desplega-ai/qa-use

Agent-first E2E testing CLI

Verdict
BLOCK
Grade
F
Trust score
48 /100
Exposed tools
19 12r · 6w · 1d
Transport
stdio · streamable-http
License
MIT
Stars
27
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

QA automation CLI for browser testing and E2E test management.

[](https://www.npmjs.com/package/@desplega.ai/qa-use) [](https://opensource.org/licenses/MIT)

[](https://www.youtube.com/watch?v=ts3XsYneiO4)

Quick Start

# Install globally
npm install -g @desplega.ai/qa-use

# Or use with npx
npx @desplega.ai/qa-use setup

Getting Started

1. Setup

qa-use setup                    # Configure your API key
qa-use test init                # Initialize test directory with example

2. Create Your First Test

Create qa-tests/login.yaml:

name: Login Test
app_config: your-app-config-id
steps:
- action: goto
url: /login
- action: fill
target: email input
value: [email protected]
- action: click
target: login button
- action: to_be_visible
target: dashboard

3. Run Tests

qa-use test run login           # Run single test
qa-use test run --all           # Run all tests

CLI Reference

Test Commands

Run qa-use test --help for all options.

Filename suffix (≥ 2.17). pull writes one file per cloud test as ${safe-name}-${short-id}.yaml, where ${short-id} is the first 8 hex chars of the test UUID. Test names can collide within an org by
Read from source at commit 2f327fc9bae6OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add qa-use --env QA_USE_API_KEY=${QA_USE_API_KEY} -- npx -y @desplega.ai/[email protected]
claude-desktop
{
  "mcpServers": {
    "qa-use": {
      "command": "npx",
      "args": [
        "-y",
        "@desplega.ai/[email protected]"
      ],
      "env": {
        "QA_USE_API_KEY": "${QA_USE_API_KEY}"
      }
    }
  }
}
03

Exposed tools (19)

12 read · 6 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
aaa_testreadGenerate a structured test scenario using the AAA (Arrange-Act-Assert) framework
ensure_installedwriteEnsure API key is set, validate authentication, and install Playwright browsers. Does not start browsers (lazy initialization on session start).
expected_outcomereadExpected outcome or success criteria
featurereadSpecific feature or functionality to test
get_configurationreadGet the current application configuration details including base URL, login settings, and viewport
interact_with_sessionreadInteract with a session - respond to questions, pause, or close the session
monitor_sessionreadMonitor a session status. Keep calling until status is
qa-usereadAI-powered browser automation and E2E testing CLI. 37 browser commands, YAML test definitions, and MCP server integration.
register_userreadRegister a new user and get API key
reset_browser_sessionsdestructiveReset and cleanup all active browser sessions. This will kill all browsers and tunnels. Use this when you hit the maximum session limit or need to free up resources.
run_automated_testswriteExecute multiple automated tests simultaneously. If a test has a matrix configured, all variants are run in parallel automatically (bounded by Hatchet
search_automated_test_runswriteSearch automated test runs with optional filtering by test ID or run ID
search_automated_testsreadSearch for automated tests by ID or query. If testId provided, returns detailed info for that test. Otherwise searches with optional query/pagination.
search_sessionsreadSearch and list all sessions (automated tests and development sessions) with pagination and filtering
start_automated_sessionwriteStart an automated E2E test session for QA flows and automated testing. Returns sessionId (data.agent_id) for monitoring. URL is optional - uses app config base_url if not provided.
start_dev_sessionwriteStart an interactive development session for debugging and exploration. Session will not auto-pilot and allows manual browser interaction.
test_typereadType of test (login, form, navigation, e-commerce, accessibility, etc.)
update_configurationwriteUpdate application configuration settings including base URL, login credentials, and viewport type
urlreadTarget URL for testing
04

Trust audit

BLOCKgrade F · trust 48/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (9 observation(s))
Shell
declared (9 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release.ts:201
await exec(`git commit -m "Release v${newVersion}"`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release.ts:209
await exec(`git tag v${newVersion}`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release.ts:213
await exec(`git push origin ${currentBranch}`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
scripts/release.ts:214
await exec(`git push origin v${newVersion}`);
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/info.ts:56
console.log(`  API Key: ${apiKey ? `${apiKey.slice(0, 12)}...` : '(not set)'}${apiKeySource}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/cli/commands/setup.ts:33
console.log(`  API key:    ${config.api_key.slice(0, 8)}...`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/http-server.ts:164
console.log(`\nAuthentication: Bearer token required (API key)`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
reset_browser_sessions
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.oxlintrc.json
.oxlintrc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.qa-use.example.json
.qa-use.example.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.vercelignore
.vercelignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.symlink · CWE-1104
AGENTS.md
AGENTS.md
Why it matters. link not followed
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/cli/lib/cli-entry.test.ts:16
argv: ['/usr/local/bin/node', '/usr/local/bin/qa-use'],
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/cli/lib/cli-entry.test.ts:17
execPath: '/usr/local/bin/node',
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/cli/lib/cli-entry.test.ts:19
if (p === '/usr/local/bin/qa-use') return '/opt/qa-use/dist/cli/index.js';
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/cli/lib/cli-entry.test.ts:24
expect(entry.command).toBe('/usr/local/bin/node');
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
src/cli/lib/cli-entry.test.ts:30
argv: ['/usr/local/bin/bun', '/repo/src/cli/index.ts'],
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
lib/api/browser.ts:7
import type { ExtendedStep } from '../../src/types/test-definition.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
lib/api/index.ts:4
import type { TestDefinition } from '../../src/types/test-definition.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
lib/api/index.ts:11
} from '../../src/types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
lib/api/index.ts:12
import type { BlockSummary, EnhancedTestSummary } from '../../src/utils/summary.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
lib/api/index.ts:18
} from '../../src/utils/summary.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
lib/env/localhost.test.ts:12
expect(isLocalhostUrl('http://127.0.0.1:5000')).toBe(true);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
lib/env/localhost.test.ts:13
expect(isLocalhostUrl('http://127.0.0.1')).toBe(true);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
lib/env/localhost.test.ts:27
expect(isLocalhostUrl('http://0.0.0.0:3000')).toBe(true);

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 2f327fc9bae6full audit observations/trust-audit/mcp-server/desplega-ai__qa-use.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-092f327fc9bae6BLOCKF48first audit
06

Questions

What is the QA-Use MCP server?

Agent-first E2E testing CLI

What tools does QA-Use expose?

19 in total: 12 read-only, 6 that write, and 1 that can delete or overwrite (reset_browser_sessions). Every one is listed on this page with its risk.

Is QA-Use safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (48/100) and found 4 critical or high issues in the source. Each one is listed on this page with the file and line it is on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does QA-Use need?

It reads QA_USE_API_KEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does QA-Use run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @desplega.ai/qa-use at 2.19.0.

How current is this page?

The grade is for one exact copy of the source (2f327fc9bae6), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement