Atlas / MCP servers / qase-tms / Qase

QaseSAFE

mcp/qase-tms/qase-1

An official Qase MCP server

Verdict
SAFE
Grade
B
Trust score
88 /100
Exposed tools
70 30r · 26w · 14d
Transport
sse · stdio · streamable-http
License
MIT
Stars
37
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Official Model Context Protocol (MCP) server for Qase Test Management Platform — connect AI assistants to your test cases, runs, defects, and more.

[](https://www.npmjs.com/package/@qase/mcp-server) [](https://opensource.org/licenses/MIT) [](https://registry.modelcontextprotocol.io/v0/servers?search=io.qase%2Fmcp-server)

Table of Contents

  • Overview
  • Use Cases
  • Quick Start
  • Use the hosted Qase MCP (recommended)
  • Run it yourself
  • Building on top of this server
  • Upgrading from v1
  • Tools
  • Documentation
  • Contributing
  • License
  • Support
  • Links

Overview

The Qase MCP Server lets AI assistants (Claude, Cursor, Codex, and any other MCP client) read and write Qase test cases, runs, results, defects, suites, milestones, and more — through a standardized protocol, with no custom integration code.

Features:

  • 40 task-oriented tools (41 total, including qase_discover_tools) — consolidated from 83 v1 tools for lower token usage and better LLM accuracy
  • Composite tools — multi-step workflows in a single call: CI reporting, defect triage, regression run setup
  • QQL support — Qase Query Language for advanced searches across cases, runs, results, defects, and plans
  • Project context bootstrap — one call returns full project structure (suites, milestones, environments, users, custom fields)
  • Test case review — propose new cases or changes for review, assign reviewers, and track status (approving and merging remain
Read from source at commit 41c50729eeeeOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add mcp-server --env QASE_API_TOKEN=${QASE_API_TOKEN} -- npx -y @qase/[email protected]
03

Exposed tools (70)

30 read · 26 write · 14 destructive. Blast radius: 14 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
areada
breadb
ci_integrationwriteReport CI/CD test results to Qase: create a run, record results, and get a summary.
complex_toolreadA complex tool
core_areada
core_creadc
core_toolreadcore
disc_breadb
duplicate_toolreadFirst
explicit_corereadcore
hiddenreadh
hidden_toolreadhidden
milestonereadMilestone name or ID
my_toolreaddesc
onboard_projectreadGet a comprehensive overview of a Qase project for a new team member:
probe_secondary_toolreadA probe tool used to verify discovery activation.
projectreadProject code (e.g. DEMO)
qase_apireadCall any Qase REST endpoint directly, for the few things no dedicated tool covers. Pass the
qase_attachment_deletedestructiveDelete an attachment by its hash. Anything referencing it — a case, a result, a defect —
qase_attachment_uploadwriteUpload files and get back the hashes that other tools reference them by — screenshots,
qase_case_bulk_createwriteCreate up to ${MAX_CASES} test cases in one request — the batch form of qase_case_upsert,
qase_case_deletedestructiveDelete a test case by project code and case ID. The case goes, and so does its execution
qase_case_upsertwriteCreate or update a single test case. With
qase_ci_reportwriteReport a whole CI run in one call: creates the run, records every result, and completes it.
qase_custom_field_deletedestructiveDelete a custom field by ID. The field disappears from every project it applies to, and the
qase_custom_field_upsertwriteCreate or update a custom field. With
qase_defect_deletedestructiveDelete a defect by project code and defect ID. The defect and its links to results
qase_defect_upsertwriteCreate or update a defect — a tracked problem found by testing. Without
qase_discover_toolsreadFind and switch on tools that are hidden by default. Only core tools appear in the tool
qase_environment_deletedestructiveDelete an environment by project code and environment ID. Runs that referenced it are not
qase_environment_upsertwriteCreate or update an environment — a named target that runs can be attributed to, such as
qase_external_issue_linkreadLink or unlink test cases and test runs to issues in an external tracker — Jira Cloud or
qase_getwriteFetch one known record by type and ID: case, suite, run, result, plan, defect, milestone,
qase_milestone_deletedestructiveDelete a milestone by project code and milestone ID. The milestone disappears and runs and
qase_milestone_upsertwriteCreate or update a milestone — a dated marker that runs and cases can be grouped under,
qase_plan_deletedestructiveDelete a test plan by project code and plan ID. Only the plan is removed — the cases it
qase_plan_upsertwriteCreate or update a test plan — a named, reusable set of cases to run together, such as a
qase_project_contextreadSeed everything about a project in one call: project details, the full suite tree,
qase_project_createwriteCreate a new project. The code must be unique in the workspace and may contain letters only
qase_project_deletedestructiveDelete an entire project by its code. This removes every test case, suite, run, result,
qase_regression_runwriteBuild and start a test run from a suite, a test plan, or an explicit list of case IDs, in
qase_result_deletedestructiveDelete a single result from a run, addressed by run ID and result hash. Use it to remove one
qase_result_recordwriteRecord up to ${MAX_RESULTS} results into an existing run. A case says what should be tested;
qase_review_bulk_createwriteOpen several test case reviews in one request — the batch form of qase_review_create, and
qase_review_createwriteOpen a test case review — the pull-request flow for test cases. Pass
qase_review_deletedestructiveDelete a review by ID. This removes the proposal entirely — it does not decline it, and
qase_review_listreadList the reviews in a project, with their current state, so you can see what is waiting on a
qase_review_updatewriteUpdate an open review: change the proposed case fields, reassign reviewers, or both.
qase_run_completewriteMark a test run as complete so it reports as finished rather than in progress. Call it once
qase_run_deletedestructiveDelete a test run by project code and run ID. This removes the run together with every
qase_run_upsertwriteCreate or update a test run. Without
qase_shared_step_deletedestructiveDelete a shared step by project code and hash. Every case that referenced it loses those
qase_shared_step_upsertwriteCreate or update a shared step — a block of steps written once and reused across many cases,
qase_suite_deletedestructiveDelete a test suite by project code and suite ID. WARNING: the cases inside are deleted with
qase_suite_upsertwriteCreate or update a test suite — the folder cases live in. Without
qase_triage_defectwriteCreate a defect from a test failure, with the failure context written into it. Requires
qql_helpreadRead the QQL reference before writing a query. Pass a
qql_searchreadSearch any entity with Qase Query Language: filtering, cross-project queries, sorting, and
regression_workflowwriteCreate and manage a full regression test cycle: set up a run from a plan or suites,
release_readinessreadCheck release readiness for a milestone: test coverage, pass rate, open defects, blocking issues.
results_jsonreadJSON array of results: [{
run_idwriteTest run ID to triage
sourcereadSource of test cases: plan ID, suite IDs (comma-separated), or
test_toolreadA test tool
titlewriteRegression run title (e.g.
to_removedestructivex
tool1readTool 1
tool2readTool 2
triage_failed_runwriteAnalyze a failed test run: show all failed results grouped by error pattern,
whoamireadreports the integration marker
04

Trust audit

SAFEgrade B · trust 88/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (2 observation(s))
Network
declared (6 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (16)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
qase_attachment_delete, qase_case_delete, qase_custom_field_delete, qase_defect_delete, qase_environment_delete, qase_milestone_delete, qase_plan_delete, qase_project_delete, qase_result_delete, qase_
Why it matters. 14 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/client/url-resolution.test.ts:109
await client.request('/v1/../../v1/project');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/operations-v2/composites/ci-report.test.ts:16
import { setTestEnv } from '../../utils/test-helpers.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/operations-v2/composites/ci-report.test.ts:24
jest.mock('../../client/index.js', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/operations-v2/composites/ci-report.test.ts:32
import { toolRegistry } from '../../utils/registry.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/operations-v2/composites/ci-report.ts:2
import { getApiClient } from '../../client/index.js';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/client/integration-headers.test.ts:47
host = `http://127.0.0.1:${(server.address() as AddressInfo).port}`;
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/transports/sse.test.ts:55
const sseUrl = new URL(`http://127.0.0.1:${(httpServer.address() as AddressInfo).port}/sse`);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/transports/sse.test.ts:168
const sseUrl = new URL(`http://127.0.0.1:${(httpServer.address() as AddressInfo).port}/sse`);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/transports/streamableHttp.elicitation.test.ts:94
baseUrl = new URL(`http://127.0.0.1:${address.port}/mcp`);
LOWPrivilege escalation / persistence · priv.escalate · CWE-269, CWE-250
.github/workflows/npm.yml:186
sudo mv mcp-publisher /usr/local/bin/
Why it matters. asks for elevated privileges
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/node, @modelcontextprotocol/server, @modelcontextprotocol/server-legacy, axios, express, express-rate-limit, form-data, jose
Why it matters. 33 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:94
- **An unparsable request body leaked a stack trace on network transports.** `express.json()` is mounted before the auth guard, so a POST with malformed JSON never reached the guard: it fell through t
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
CHANGELOG.md:122
- **Each SSE client gets its own session.** The transport kept one connection per process, so the second client to open `/sse` took over the first one's stream and the original session silently stoppe
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/self-run.md:73
Over HTTP transports the marker can also travel per request instead of per process — send an `X-Qase-Integration: <name>/<version>` header, or add `?integration=<name>/<version>` to the MCP endpoint U
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/troubleshooting.md:188
2. 2.6.0 also fixes notification delivery on the HTTP transports, where only the most recently opened session used to be notified — if several sessions or clients share one server process, older sessi
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 41c50729eeeefull audit observations/trust-audit/mcp-server/qase-tms__qase-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0841c50729eeeeSAFEB88first audit
06

Questions

What is the Qase MCP server?

An official Qase MCP server

What tools does Qase expose?

70 in total: 30 read-only, 26 that write, and 14 that can delete or overwrite (qase_attachment_delete, qase_case_delete, qase_custom_field_delete, qase_defect_delete, qase_environment_delete). Every one is listed on this page with its risk.

Is Qase safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (88/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 14 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Qase need?

It reads DUMP_TOKEN, QASE_API_TOKEN, QASE_OAUTH_AUDIENCE, QASE_OAUTH_ENABLED, QASE_OAUTH_ISSUER, QASE_OAUTH_JWT_ALGORITHMS, QASE_OAUTH_PUBLIC_URL, QASE_OAUTH_RESOURCE_URL and QASE_OAUTH_REVOCATION_URL from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Qase run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as @qase/mcp-server at 2.7.5.

How current is this page?

The grade is for one exact copy of the source (41c50729eeee), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement