Security & Testing
testorax.com
Provides access to Testorax health, run listings, bug reports, and proof packets for QA and security testing.
ENDPOINT 1
https://testorax.com/mcp
Known tools 136
testorax_mcp_self_checkRead-only health check for Testorax MCP.
list_runsList recent Testorax runs for the configured email.
get_reportFetch the full bug report for a completed run.
fetch_proof_packFetch the agent-readable proof pack for a run.
fetch_proof_packetFetch the agent-readable Proof Packet for a run (Agent Fix Loop).
get_agent_summaryGet the unified agent summary for a run.
get_routesGet the Route Discovery projection for a run (contract 1.0.0).
validate_assertionValidate and compile a closed-set assertion helper into runner-supported TestSteps.
campaign_previewPreview an autonomous QA campaign for a target URL.
campaign_progressGet the live progress snapshot for a campaign preview job.
campaign_preview_jobPoll a Stage C/D/F real-browser preview job.
campaign_parityStage F parity surface for a campaign preview job.
campaign_executeStage H: confirm a campaign preview and queue page-by-page execution.
campaign_statusStage H: get full campaign execution status (campaign + page-runs + progress + proofSummary).
campaign_run_progressStage H/E: get a compact live progress snapshot for either a preview job (prv_<22>) or a campaign (cmp_<22>).
campaign_issuesStage I: read all issues + proof packets + AI fix prompts for a campaign.
campaign_patch_batchesStage I: read patch batches for a campaign.
campaign_fix_promptStage I: get the AI Fix Prompt for one campaign issue.
campaign_baselineStage I: read campaign baseline + rerun plan.
verify_fixCompare two arbitrary runs (original failure + verification rerun) and return a closed-set 12-status verdict envelope (fixed_verified | still_reproduces | partially_fixed | unable_to_verify | flaky | regression_reopened | selector_changed | route_missing | auth_blocked | environment_changed | proof_changed_but_not_verified | unknown).
get_visual_layoutGet the Visual / Mobile Layout Intelligence v1 envelope for a run (contract 1.0.0).
get_safe_test_dataGet the Safe Test Data Mode envelope for a run (contract 1.0.0).
get_app_mapGet the App Intelligence Map / Proof Graph Dashboard v1 envelope for a run (contract 1.0.0).
get_patch_batchesPatch Batch Verification State Tracking v1 (contract 1.0.0).
get_patch_batchSingle patch batch envelope by id (pb_<runId>_<8hex>).
fix_check_startStage J: start a Fix Check on a campaign.
fix_check_statusStage J: read full Fix Check status + verdict + before/after comparison.
fix_check_progressStage J: compact live progress snapshot for a Fix Check.
fix_check_verdictStage J: shorthand for fetching ONLY the verdict + comparison + doNotClaim of a Fix Check.
compare_runsCompare baseline vs current run.
suggest_patch_batchesSuggest patch batches (groups of failing issues to fix together) by comparing baseline vs current run.
summarize_run_changesCompact summary of what changed between baseline and current run.
detect_proof_weakeningDetect whether the current run shrank proof coverage vs the baseline.
get_validation_summaryGet validation runtime summary for a run.
get_validation_evidenceGet full validation runtime evidence for a run: every probe with classification, DOM signals, formSelector, targetUrl, note, capturedAt.
get_auth_coverageGet the authenticated coverage runtime envelope for a run (contract 1.0.0).
get_auth_routesGet per-route authenticated route discovery for a run.
get_auth_continuityGet auth continuity intelligence for a run.
get_run_intelligenceGet Proof Memory classification for a run.
get_history_intelligenceGet aggregated Proof Memory across the caller's runs (last 30 days by default; max 90).
get_code_hintsGet code-aware fix hints for a run.
get_compact_proofGet the Compact Proof Summary for a run — small (~1–3 KB) agent-first JSON with verdict, trustScore, failureType, failedStep, whatHappened/whatIsProven/whatIsNotProven, latestScreenshot pointer (if available), proofPacketUrl/exportUrl/runIntelligenceUrl, fixCheck recommendation, nextSafeAction, aiFixPromptCompact, doNotClaim.
get_operational_depthGet the Operational Depth Layer v1 result for a run — universal classifier (not app-specific) that tells apart shallow public / login-wall / SPA-shell runs from runs that exercised authenticated operational surfaces.
get_traversal_runtimeGet the Stateful Traversal Runtime substrate v1 result for a run — universal substrate (not app-specific) returning transition fingerprints, traversal memory (visitedStates / visitedRoutes / repeatedSelectors / noOpSelectors / modalBranches / authRedirects / deadEnds / branchDepth / branchBreadth), runtime novelty (uniqueTransitionRatio / repeatedTransitionRatio / noOpTransitionRatio / branchExpansionRatio / actionNoveltyScore / runtimeStagnationRisk), workflow continuity verdict (closed set: workflow_chains_detected / workflow_chains_partial / workflow_chains_blocked / workflow_dead_ends_present / no_workflow_signal — NOTE workflow_chains_verified is NEVER claimed by substrate), runtimeStagnationWarnings, doNotClaim.
get_screenshot_recommendationGet just the screenshot-on-demand recommendation block for a run, without the rest of the compact proof.
get_browser_capabilitiesGet the Vibe Browser Engine capability matrix.
get_capabilitiesGet the agent-readable Testorax capability map.
audit_previewOne-flow audit plan: given a target URL, return what will be tested, what will not, blocked reasons, recommended mode (public_fast_scan / authenticated_smoke / full_crud_e2e / campaign_execution / blocked), the exact next CLI command, proof scopes expected, and Chrome parity recommendation.
get_live_run_statusGet the live status + recent proof events for a run (Watch Test Live).
list_auth_sessionsList the caller's Login Memory entries (saved logins).
get_auth_sessionGet one Login Memory entry by id.
revoke_auth_sessionRevoke a Login Memory entry.
list_login_memoryList the caller's Login Memory (saved authenticated session) profiles.
validate_login_memoryValidate a Login Memory profile.
poll_login_memory_validationPoll a live Login Memory validation job.
delete_login_memoryDelete (revoke) a Login Memory profile.
create_auth_profileCreate a Login Memory profile by driving a real browser login on the cloud-side Hetzner runner.
audit_runExecute a previously-previewed audit safely.
launch_readinessCompute a conservative launch-readiness verdict from caller-supplied evidence (compact proofs, audit preview/run, Chrome parity, cleanup result).
classify_evidenceClassify a normalized evidence record using the False-Positive Classifier (Hardening Batch 1).
list_screenshotsList all screenshots stored for a run (raw PNGs + AB-2 marked annotations).
get_screenshotGet a safe authenticated URL + caption for a specific screenshot by id.
get_latest_screenshotGet the most-recent screenshot for a run.
get_marked_screenshotGet the most-recent Marked Proof Screenshot for a run.
start_fix_checkSTARTS a Fix Check on a previously-failed run — creates a regression_check verify run that re-executes the original failing scenarios with the same-assertion lock.
get_fix_check_resultRead the Fix Check verdict for a verify run.
get_visual_findingsFetch Visual Quality / Vibe QA findings for a completed run.
get_mutation_proofFetch mutation proof for a scenario_runner run.
run_statusGet live status of a run.
run_timelineGet the chronological state timeline for a run.
run_summary_mdGet a markdown narrative summary of a run, optimized for LLM consumption.
failure_contextGet complete diagnostic context for a failed scenario: failed step, error, screenshot, DOM snapshot, console errors, network, blocked cookies.
regressionsFind scenarios that regressed — were passing on the last N runs and just broke.
get_scenario_schemaFetch the canonical JSON Schema for scenarios.
list_actionsList every supported step action with required/optional fields and examples.
get_run_statesGet the run state diagram: every state, valid transitions, and when you can inject scenarios.
validate_scenariosDry-run validate a scenarios array.
list_suitesList saved test suites.
list_variablesList saved variables (KV pairs).
list_reposList GitHub repos registered to the account.
list_app_groupsList app groups (multi-URL test bundles).
list_creditsList active promo codes / credits on this account.
get_dashboardFetch account dashboard KPIs: pass rate, critical issues, spend, daily series, top failing scenarios.
list_messagesList sent messages and replies.
install_github_appGet the GitHub App install URL.
create_bypass_runCreate a run with custom scenarios (no browser payment).
retry_failedRe-run only the failed scenarios from a previous run.
cancel_runCancel a queued/running/awaiting_human run.
run_suiteTrigger a saved suite by slug.
run_app_groupTrigger all URLs in an app group simultaneously.
set_variableSave a variable.
send_messageAsk the human owner a question during a run.
get_pricingPAYG prices + subscription plans.
get_usageCustomer plan, calendar-month usage by mode, wallet balance, remaining allowance.
check_free_audit_eligibilityRead-only check whether (email, URL) is free-audit-eligible.
register_appREGISTERS a deployed website/app under the caller's account.
start_free_fast_bug_scanSTARTS the one-time FREE Fast Bug Scan (uses the trial credit).
list_test_modesList the four Testorax test modes with their requirements, risk level, and whether agent config is needed.
list_test_templatesList all Workflow + Deep CRUD templates the agent can use as scaffolds.
get_test_templateFetch one template by id.
validate_template_inputsPure shape check: does the agent have every required field for this template?
generate_template_promptGenerate the copy-paste agent prompt for a template.
list_scenario_templatesList all Scenario Template Library templates (41 ready-made scenarios covering auth, CRUD, search, pagination, forms, editor, commerce, communication, file, permissions, resilience, mobile, accessibility, multi-tenant, feature-flags, realtime, localization, data-export, data-import).
get_scenario_templateFetch one scenario template by id.
generate_scenario_from_templateGenerate a complete fillable scenario JSON from a template + caller-supplied variables.
recommend_next_testRecommend the next test for a given run.
start_fast_bug_scanSTARTS a new Fast Bug Scan run on a deployed URL — opens the app in a real browser, clicks every safe visible control, reports breakages.
start_fast_bug_huntSTARTS a Continuous Bug Hunt — crawls the URL and stops on the first high-confidence (severity=high, confidence>=0.8) issue.
start_regression_checkSTARTS a Verify Fixes run — re-executes the failing interactions from a prior run, specific findings/issues, or all open issues for an app.
prepare_workflow_testSTARTS a Workflow Test by submitting a multi-step user journey config (login → checkout, signup → confirm, create-project → invite-collaborator).
start_authenticated_smokeSTARTS an Authenticated Smoke Test — visits each provided route under a saved Login Memory profile and captures per-route classification (ok / blank_content / page_error / fetch_failed / auth_lost / timeout / navigation_error / console_error_only).
prepare_crud_e2e_configVALIDATES a CrudConfig for Deep CRUD E2E.
ask_runAsk a grounded question about a run.
get_run_chat_historyFetch the full chat history for a run — every question and answer, in order.
verify_fixes_resultsRead the Verify Fixes ledger for a regression_check run.
start_live_click_auditStart a Live Click Audit on a deployed app URL.
get_live_click_audit_statusLive progress of a Live Click Audit run.
get_live_click_audit_findingsFull Live Click Audit findings sorted by severity.
get_latest_run_errorsMost recent critical/high/medium errors from a run, combining Live Click Audit findings AND normal scenario failures.
rerun_failed_clicksRerun every failed click from a previous Live Click Audit.
get_bug_memory_matchesFor every finding in a run, return the matched bug_memory row (if any).
mark_finding_feedbackLabel a finding (confirmed_bug | fixed_verified | false_positive | expected_behavior | ignored | fixed_unverified).
learn_from_runBulk: confirm Bug Memory rows for every already-labelled finding in this run.
get_similar_past_bugsFindings in this run that match a past bug memory row.
get_project_memoryRead .testorax/rules.md / live-click.md / ignore.md for a project (by hostname or orgId+appId).
set_project_memoryWrite/update a .testorax/{rules,live-click,ignore}.md file for a project.
report_issue_to_testoraxReport a bug to the central Testorax issue inbox.
get_open_issues_for_appFetch every open issue for an app, sorted by severity + recency.
get_issue_detailsGet one issue by id.
update_issue_statusMove an issue between statuses (open | in_progress | fixed | fixed_verified | ignored | false_positive | expected_behavior).
attach_issue_to_runLink an existing issue to a Testorax run.
search_testorax_issuesSearch the central issue inbox.
discover_configGenerate draft Workflow/CRUD/Campaign configs from existing evidence (report.json / proof packet / live scan / known routes).
confirm_configConfirm a draft config (workflow/crud/campaign) — does NOT execute.
preview_authenticated_auditPreview a universal authenticated audit on a Testorax-owned target.
execute_authenticated_auditExecute a universal authenticated audit on a Testorax-owned target.