OctomindSAFE
An MCP server for octomind tools, resources and prompts
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@OctoMind-dev/octomind-mcp)
Octomind provides a whole e2e platform for test creation, execution and management including auto-fix. With this MCP server you can use Octomind tools and resources in your local development environment and enable it to create new e2e tests, execute them and more. see https://octomind.dev/ and https://octomind.dev/docs/mcp/install-octomind-mcp for more details.
See it in action together with testrail mcp
[](https://www.youtube.com/watch?v=I7lc9I0S62Y)
Configuration
Environment Variables
The server uses the following environment variables:
APIKEY- The API key for Octomind API (required)OCTOMIND_API_URL- Base URL for the API endpoint to use (defaults to https://app.octomind.dev/api)REDIS_URL- Redis connection URL for session storage (optional, format: redis://host:port)SESSION_EXPIRATION_SECONDS- Time in seconds after which sessions expire (optional, Redis only)
Command Line Options
The server supports the following command line options:
-s, --sse- Enable SSE transport mode-t, --stream- Enable Streamable HTTP transport mode-c, --clients- Show client configuration examples-p, --port- Port to listen on (default: 3000)-r, --redis-url- Redis URL for session storage-e, --session-expiration- Session expiration time in seconds
Session Storage
The server supports two types of session storage:
- In-memory storage (default) - Sessions are stored in memory and will be lost when the server restarts
- Redis storage - Sessions are stored in Redis and can persist across server restarts
For production deployments, it's recommended to use Redis storage w
99ca2ea87533OBSERVED · 2026-10-09Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add octomind-mcp --env APIKEY=${APIKEY} -- npx -y @octomind/[email protected]{
"mcpServers": {
"octomind-mcp": {
"command": "npx",
"args": [
"-y",
"@octomind/[email protected]"
],
"env": {
"APIKEY": "${APIKEY}"
}
}
}
}Exposed tools (21)
11 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
createBatchGeneration | write | create a batch discovery for a given test target. Useful to generate multiple test cases from a prompt and optional images in one go |
createEnvironment | write | the createEnvironment tool can create an environment for a given test target. an environment represents a specific setup or deployments for a test target. It include a test account when necsesary to login, a header configuration, a discovery url and a set of variables. |
createFromTestPlan | write | create test cases from a test plan for a given test target. Provide freeform text, related images and tag names to assign |
createTestTarget | write | the createTestTarget tool can create a new test target or project. A test target represents an application or service that can be tested using Octomind. |
deleteEnvironment | read | |
deleteTestTarget | destructive | the deleteTestTarget tool can delete an existing test target. This operation cannot be undone. |
discovery | write | the discovery tool can create a test case on a given test target with a test case description or prompt. One can either start from the predefined url for that test case or provide a new entry point url. |
executeTests | write | the executeTests tool can trigger a set of tests for a given test target. The test target id is unique to the test target. The tests are executed on the provided url. The context object is used to provide information about the source of the test execution. |
getEnvironments | read | the getEnvironments tool can retrieve environments for a given test target. an environment represents a specific setup or deployments for a test target. It include a test account when necsesary to login, a header configuration, a discovery url and a set of variables. |
getPrivateLocations | read | the getPrivateLocations tool can retrieve all private locations configured for that org. A private location is a server that can be used to access a test target behind a firewall or VPN. |
getTestCase | read | the getTestCase tool can retrieve a test case for a given test target and test case id. A test case id is unique to the test target. The test case includes a set of interactions and assertions. it is the result of a discovery or a manual creation. |
getTestCases | read | the getTestCases tool can retrieve test cases for a given test target with optional filtering. Test cases can be filtered by various criteria such as status, description, or tags. |
getTestReport | read | the getTestReport tool can retrieve a test report for a given test target and test report id. A test report id is generated when a set of test are executed on a test target. The test report id is unique to the test target. |
getTestReports | read | the getTestReports tool can retrieve test reports for a given test target. Test reports are generated when set of tests are executed. The test report id is unique to the test target. |
getTestTargets | read | the getTestTargets tool can retrieve all test targets or projects. Test targets represent applications or services that can be tested using Octomind. |
getVersion | read | Returns the current version of the Octomind MCP server |
search | read | the search tool can be used to search the octomind documentation for a given query. The search results are returned as a list of links to the documentation. |
updateEnvironment | write | the updateEnvironment tool can update an environment for a given test target. An environment represents a specific setup or deployments for a test target. It includes a test account when necessary to login, a header configuration or a discovery url. |
updateTestCase | write | the updateTestCase tool can update specific properties of a test case. This allows modifying test case details such as description, status, or folderName. |
updateTestCaseElement | read | |
updateTestTarget | write | the updateTestTarget tool can update an existing test target. A test target represents an application or service that can be tested using Octomind. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (4 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (2)
deleteTestTarget
.eslintignore
Gates applied: no_behavioural_pass.
99ca2ea87533full audit observations/trust-audit/mcp-server/octomind-dev__octomind.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-09 | 99ca2ea87533 | SAFE | B | 89 | first audit |
Questions
What is the Octomind MCP server?
An MCP server for octomind tools, resources and prompts
What tools does Octomind expose?
21 in total: 11 read-only, 9 that write, and 1 that can delete or overwrite (deleteTestTarget). Every one is listed on this page with its risk.
Is Octomind safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Octomind need?
It reads APIKEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Octomind run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @octomind/octomind-mcp at 1.4.1.
How current is this page?
The grade is for one exact copy of the source (99ca2ea87533), read on 2026-10-09. The repository is watched and re-audited when it changes.