# redmine-mcp-connector

stdio MCP server wrapping the Redmine REST API: issues, projects, users, time, wiki, versions.

- **Type:** MCP server
- **Trust:** 40/100 (C), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 1.0.1
- **Author:** io.github.Nikhilprasad-r
- **License:** Unknown
- **npm:** redmine-mcp-connector
- **Source:** https://github.com/Nikhilprasad-r/redmine-mcp-server
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

40/100 (C), scored on the package rubric
- Publisher verified: no
- Install scripts: suspicious script found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 11 days

## Security scan

- **Status:** warnings
- **Scanned:** 2026-09-24T19:07:26.462Z
- **Version scanned:** 1.0.1
- **CVEs:** none found by OSV at scan time
**Findings**
- injection-shaped content (warning) in the `redmine_attachment_upload` tool: Exfiltration-shaped instruction

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `redmine_search` — Search Redmine (GET /search.json).
- `redmine_attachment_get` — Get attachment metadata (GET /attachments/:id.json).
- `redmine_attachment_update` — Update attachment metadata (PUT /attachments/:id.json).
- `redmine_attachment_delete` — Delete attachment (DELETE /attachments/:id.json). Requires confirm: true.
- `redmine_attachment_upload` — Upload a file to Redmine (POST /uploads.json). Returns upload token; attach via issue/wiki update using uploads array.
- `redmine_attachment_download` — Download attachment binary (GET /attachments/download/:id.json or .bin). Returns base64 and content_type; size capped by REDMINE_MAX_DOWNLOAD_BYTES.
- `redmine_repository_revision_link_issue` — Link an issue to a repository changeset (POST /projects/:id/repository/:repository_id/revisions/:rev/issues.json). Requires API permission on repository.
- `redmine_repository_revision_unlink_issue` — Unlink an issue from a changeset (DELETE .../revisions/:rev/issues/:issue_id.json). Requires confirm: true.
- `redmine_groups_list` — List groups (GET /groups.json). May require admin permissions.
- `redmine_group_get` — Get group (GET /groups/:id.json).
- `redmine_issues_list` — List issues (GET /issues.json). Supports filters and optional fetch_all to merge pages.
- `redmine_issue_get` — Get a single issue (GET /issues/:id.json).
- `redmine_issue_create` — Create an issue (POST /issues.json). Body uses Redmine issue JSON shape.
- `redmine_issue_update` — Update an issue including notes/comments (PUT /issues/:id.json). Pass issue fields and optional notes.
- `redmine_issue_add_comment` — Add a journal note to an issue (same as update with notes only).
- `redmine_issue_delete` — Delete an issue (DELETE /issues/:id.json). Requires confirm: true.
- `redmine_issue_add_watcher` — Add a watcher to an issue (POST /issues/:id/watchers.json).
- `redmine_issue_remove_watcher` — Remove a watcher from an issue (DELETE /issues/:issue_id/watchers/:user_id.json).
- `redmine_issue_relations_list` — List relations for an issue (GET /issues/:id/relations.json).
- `redmine_issue_add_relation` — Add a relation between issues (POST /issues/:id/relations.json).
- `redmine_issue_remove_relation` — Delete an issue relation (DELETE /relations/:id.json). Requires confirm: true.
- `redmine_project_memberships_list` — List project memberships (GET /projects/:id/memberships.json).
- `redmine_membership_create` — Create membership (POST /projects/:project_id/memberships.json).
- `redmine_membership_update` — Update membership (PUT /memberships/:id.json).
- `redmine_membership_delete` — Delete membership (DELETE /memberships/:id.json). Requires confirm: true.
- `redmine_news_list` — List news (GET /news.json).
- `redmine_news_get` — Get news item (GET /news/:id.json).
- `redmine_news_create` — Create news (POST /projects/:project_id/news.json or POST /news.json with project identifier).
- `redmine_news_update` — Update news (PUT /news/:id.json).
- `redmine_news_delete` — Delete news (DELETE /news/:id.json). Requires confirm: true.
- `redmine_projects_list` — List projects (GET /projects.json).
- `redmine_project_get` — Get project (GET /projects/:id.json).
- `redmine_project_create` — Create project (POST /projects.json).
- `redmine_project_update` — Update project (PUT /projects/:id.json).
- `redmine_project_archive` — Archive project (PUT /projects/:id/archive.json).
- `redmine_project_unarchive` — Unarchive project (PUT /projects/:id/unarchive.json).
- `redmine_project_delete` — Delete project (DELETE /projects/:id.json). Requires confirm: true.
- `redmine_request` — Escape hatch: arbitrary Redmine REST call (disabled unless REDMINE_ALLOW_RAW_REQUEST=true). DELETE requires confirm: true.
- `redmine_time_entries_list` — List time entries (GET /time_entries.json).
- `redmine_time_entry_get` — Get time entry (GET /time_entries/:id.json).

## Install

**Verdict: do-not-install** — Do not install: 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it.
**Blocking**
- 1 injection-shaped pattern found in this entry's own text — it may try to steer the model that loads it. — tool:redmine_attachment_upload: Exfiltration-shaped instruction
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Client configuration withheld.** Client configs are withheld because this entry has a blocking finding. Show the warnings below to the person installing it.
If they have seen the findings and still want to proceed, request the plan again with acknowledge_warnings=true.

## Blast radius

Extensive blast radius — deletes data; holds an api key.
- Floor 58, ceiling 58 (tier: extensive)
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/redmine-mcp-connector
- Install plan: https://forgeregistry.com/api/v1/packages/redmine-mcp-connector/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/redmine-mcp-connector
- HTML page: https://forgeregistry.com/registry/redmine-mcp-connector
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
