BrunoSAFE
🚀 MCP server for generating Bruno API testing files programmatically. Create collections, environments, requests, and test scripts using AI clients like Claude Desktop.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for generating Bruno API testing files programmatically.
Overview
Bruno MCP Server enables you to create, manage, and generate Bruno API testing collections, environments, and requests through standardized MCP tools. This allows for automated setup of API testing workflows and integration with Claude and other MCP-compatible clients.
Features
- 📁 Collection Management: Create and organize Bruno collections
- 🌍 Environment Configuration: Manage multiple environments (dev, staging, prod)
- 🔧 Request Generation: Generate .bru files for all HTTP methods
- 🔐 Authentication Support: Bearer tokens, Basic auth, OAuth 2.0, API keys
- 📝 Test Scripts: Add pre/post request scripts and assertions
- 🔄 CRUD Operations: Generate complete CRUD request sets
- 📊 Collection Statistics: Analyze existing collections
Installation
# Clone the repository git clone https://github.com/macarthy/bruno-mcp.git cd bruno-mcp # Install dependencies npm install # Build the project npm run build
Client Integration
The Bruno MCP Server can be integrated with various AI clients that support the Model Context Protocol:
Quick Setup for Claude Desktop
- Edit Claude Desktop config file:
- macOS:
~/Library/Application Support/Claude/claude_desktop_config.json - Windows:
%APPDATA%/Claude/claude_desktop_config.json - Linux:
~/.config/Claude/claude_desktop_config.json
- Add Bruno MCP Server:
{
"mcpServers": {
"bruno-mcp": {
"command": "node",
"args": ["/absolute/path/to/bruno-mcp/dist/index.js"],
"env": {}
}
}
}- Restart Claude Desktop
Supported Clients
- ✅ Claude Desktop App - Full support
- ✅ Claude Code (VS Code) - Full support
- ✅ Continue - Tools and resources
- ✅ Cline - Tools and resources
- ✅ LM Studio - Tools support
- ✅ **MCP Inspe
08236b5cb195OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add bruno-mcp -- npx -y [email protected]
{
"mcpServers": {
"bruno-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (8)
2 read · 6 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
add_test_script | write | |
create_collection | write | |
create_crud_requests | write | |
create_environment | write | |
create_request | write | |
create_test_suite | write | |
get_collection_stats | read | |
list_collections | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
@modelcontextprotocol/sdk, zod, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser, eslint, jest, @types/jest
MCP clients **MUST NOT** send tokens to the MCP server other than ones issued by the MCP server's authorization server.
Client->>+Server: POST InitializedNotification<br>Mcp-Session-Id: 1868a90c...
Client->>+Server: POST ... request ...<br>Mcp-Session-Id: 1868a90c...
Client->>+Server: POST ... notification/response ...<br>Mcp-Session-Id: 1868a90c...
load_dotenv() # load environment variables from .env
This creates the beginnings of a .NET console application that can read the API key from user secrets.
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
08236b5cb195full audit observations/trust-audit/mcp-server/macarthy__bruno.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 08236b5cb195 | SAFE | B | 89 | first audit |
Questions
What is the Bruno MCP server?
🚀 MCP server for generating Bruno API testing files programmatically. Create collections, environments, requests, and test scripts using AI clients like Claude Desktop.
What tools does Bruno expose?
8 in total: 2 read-only, 6 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Bruno safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Bruno need?
No credential environment variables were found in its source, so it appears to need none.
How does Bruno run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as bruno-mcp at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (08236b5cb195), read on 2026-10-09. The repository is watched and re-audited when it changes.