Atlas / MCP servers / octomind-dev / Octomind

OctomindSAFE

mcp/octomind-dev/octomind

An MCP server for octomind tools, resources and prompts

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
21 11r · 9w · 1d
Transport
sse · stdio · streamable-http
License
MIT
Stars
24
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@OctoMind-dev/octomind-mcp)

Octomind provides a whole e2e platform for test creation, execution and management including auto-fix. With this MCP server you can use Octomind tools and resources in your local development environment and enable it to create new e2e tests, execute them and more. see https://octomind.dev/ and https://octomind.dev/docs/mcp/install-octomind-mcp for more details.

See it in action together with testrail mcp

[](https://www.youtube.com/watch?v=I7lc9I0S62Y)

Configuration

Environment Variables

The server uses the following environment variables:

  • APIKEY - The API key for Octomind API (required)
  • OCTOMIND_API_URL - Base URL for the API endpoint to use (defaults to https://app.octomind.dev/api)
  • REDIS_URL - Redis connection URL for session storage (optional, format: redis://host:port)
  • SESSION_EXPIRATION_SECONDS - Time in seconds after which sessions expire (optional, Redis only)

Command Line Options

The server supports the following command line options:

  • -s, --sse - Enable SSE transport mode
  • -t, --stream - Enable Streamable HTTP transport mode
  • -c, --clients - Show client configuration examples
  • -p, --port - Port to listen on (default: 3000)
  • -r, --redis-url - Redis URL for session storage
  • -e, --session-expiration - Session expiration time in seconds

Session Storage

The server supports two types of session storage:

  1. In-memory storage (default) - Sessions are stored in memory and will be lost when the server restarts
  2. Redis storage - Sessions are stored in Redis and can persist across server restarts

For production deployments, it's recommended to use Redis storage w

Read from source at commit 99ca2ea87533OBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add octomind-mcp --env APIKEY=${APIKEY} -- npx -y @octomind/[email protected]
claude-desktop
{
  "mcpServers": {
    "octomind-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@octomind/[email protected]"
      ],
      "env": {
        "APIKEY": "${APIKEY}"
      }
    }
  }
}
03

Exposed tools (21)

11 read · 9 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
createBatchGenerationwritecreate a batch discovery for a given test target. Useful to generate multiple test cases from a prompt and optional images in one go
createEnvironmentwritethe createEnvironment tool can create an environment for a given test target. an environment represents a specific setup or deployments for a test target. It include a test account when necsesary to login, a header configuration, a discovery url and a set of variables.
createFromTestPlanwritecreate test cases from a test plan for a given test target. Provide freeform text, related images and tag names to assign
createTestTargetwritethe createTestTarget tool can create a new test target or project. A test target represents an application or service that can be tested using Octomind.
deleteEnvironmentread
deleteTestTargetdestructivethe deleteTestTarget tool can delete an existing test target. This operation cannot be undone.
discoverywritethe discovery tool can create a test case on a given test target with a test case description or prompt. One can either start from the predefined url for that test case or provide a new entry point url.
executeTestswritethe executeTests tool can trigger a set of tests for a given test target. The test target id is unique to the test target. The tests are executed on the provided url. The context object is used to provide information about the source of the test execution.
getEnvironmentsreadthe getEnvironments tool can retrieve environments for a given test target. an environment represents a specific setup or deployments for a test target. It include a test account when necsesary to login, a header configuration, a discovery url and a set of variables.
getPrivateLocationsreadthe getPrivateLocations tool can retrieve all private locations configured for that org. A private location is a server that can be used to access a test target behind a firewall or VPN.
getTestCasereadthe getTestCase tool can retrieve a test case for a given test target and test case id. A test case id is unique to the test target. The test case includes a set of interactions and assertions. it is the result of a discovery or a manual creation.
getTestCasesreadthe getTestCases tool can retrieve test cases for a given test target with optional filtering. Test cases can be filtered by various criteria such as status, description, or tags.
getTestReportreadthe getTestReport tool can retrieve a test report for a given test target and test report id. A test report id is generated when a set of test are executed on a test target. The test report id is unique to the test target.
getTestReportsreadthe getTestReports tool can retrieve test reports for a given test target. Test reports are generated when set of tests are executed. The test report id is unique to the test target.
getTestTargetsreadthe getTestTargets tool can retrieve all test targets or projects. Test targets represent applications or services that can be tested using Octomind.
getVersionreadReturns the current version of the Octomind MCP server
searchreadthe search tool can be used to search the octomind documentation for a given query. The search results are returned as a list of links to the documentation.
updateEnvironmentwritethe updateEnvironment tool can update an environment for a given test target. An environment represents a specific setup or deployments for a test target. It includes a test account when necessary to login, a header configuration or a discovery url.
updateTestCasewritethe updateTestCase tool can update specific properties of a test case. This allows modifying test case details such as description, status, or folderName.
updateTestCaseElementread
updateTestTargetwritethe updateTestTarget tool can update an existing test target. A test target represents an application or service that can be tested using Octomind.
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (2)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deleteTestTarget
Why it matters. 1 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.eslintignore
.eslintignore
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 99ca2ea87533full audit observations/trust-audit/mcp-server/octomind-dev__octomind.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0999ca2ea87533SAFEB89first audit
06

Questions

What is the Octomind MCP server?

An MCP server for octomind tools, resources and prompts

What tools does Octomind expose?

21 in total: 11 read-only, 9 that write, and 1 that can delete or overwrite (deleteTestTarget). Every one is listed on this page with its risk.

Is Octomind safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Octomind need?

It reads APIKEY from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Octomind run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @octomind/octomind-mcp at 1.4.1.

How current is this page?

The grade is for one exact copy of the source (99ca2ea87533), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement