Atlas / MCP servers / macarthy / Bruno

BrunoSAFE

mcp/macarthy/bruno

🚀 MCP server for generating Bruno API testing files programmatically. Create collections, environments, requests, and test scripts using AI clients like Claude Desktop.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
8 2r · 6w · 0d
Transport
stdio
License
MIT
Stars
35
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for generating Bruno API testing files programmatically.

Overview

Bruno MCP Server enables you to create, manage, and generate Bruno API testing collections, environments, and requests through standardized MCP tools. This allows for automated setup of API testing workflows and integration with Claude and other MCP-compatible clients.

Features

  • 📁 Collection Management: Create and organize Bruno collections
  • 🌍 Environment Configuration: Manage multiple environments (dev, staging, prod)
  • 🔧 Request Generation: Generate .bru files for all HTTP methods
  • 🔐 Authentication Support: Bearer tokens, Basic auth, OAuth 2.0, API keys
  • 📝 Test Scripts: Add pre/post request scripts and assertions
  • 🔄 CRUD Operations: Generate complete CRUD request sets
  • 📊 Collection Statistics: Analyze existing collections

Installation

# Clone the repository
git clone https://github.com/macarthy/bruno-mcp.git
cd bruno-mcp

# Install dependencies
npm install

# Build the project
npm run build

Client Integration

The Bruno MCP Server can be integrated with various AI clients that support the Model Context Protocol:

Quick Setup for Claude Desktop

  1. Edit Claude Desktop config file:
  2. macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  3. Windows: %APPDATA%/Claude/claude_desktop_config.json
  4. Linux: ~/.config/Claude/claude_desktop_config.json
  1. Add Bruno MCP Server:
{
"mcpServers": {
"bruno-mcp": {
"command": "node",
"args": ["/absolute/path/to/bruno-mcp/dist/index.js"],
"env": {}
}
}
}
  1. Restart Claude Desktop

Supported Clients

  • ✅ Claude Desktop App - Full support
  • ✅ Claude Code (VS Code) - Full support
  • ✅ Continue - Tools and resources
  • ✅ Cline - Tools and resources
  • ✅ LM Studio - Tools support
  • ✅ **MCP Inspe
Read from source at commit 08236b5cb195OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add bruno-mcp -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "bruno-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ]
    }
  }
}
03

Exposed tools (8)

2 read · 6 write · 0 destructive.

ToolRiskDescription
add_test_scriptwrite
create_collectionwrite
create_crud_requestswrite
create_environmentwrite
create_requestwrite
create_test_suitewrite
get_collection_statsread
list_collectionsread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, zod, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, jest, @types/jest
Why it matters. 12 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/mcp.md:9335
MCP clients **MUST NOT** send tokens to the MCP server other than ones issued by the MCP server's authorization server.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/mcp.md:10289
Client->>+Server: POST InitializedNotification<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/mcp.md:10293
Client->>+Server: POST ... request ...<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/mcp.md:10306
Client->>+Server: POST ... notification/response ...<br>Mcp-Session-Id: 1868a90c...
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/mcp.md:5195
load_dotenv()  # load environment variables from .env
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
docs/mcp.md:6573
This creates the beginnings of a .NET console application that can read the API key from user secrets.
Why it matters. asks the agent to read credentials
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
docs/mcp.md:6823
curl -LsSf https://astral.sh/uv/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 08236b5cb195full audit observations/trust-audit/mcp-server/macarthy__bruno.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0908236b5cb195SAFEB89first audit
06

Questions

What is the Bruno MCP server?

🚀 MCP server for generating Bruno API testing files programmatically. Create collections, environments, requests, and test scripts using AI clients like Claude Desktop.

What tools does Bruno expose?

8 in total: 2 read-only, 6 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Bruno safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Bruno need?

No credential environment variables were found in its source, so it appears to need none.

How does Bruno run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as bruno-mcp at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (08236b5cb195), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement