Trail
NPM · USETRAIL · SCANNED SEP 21
Issue tracker and durable project memory for your coding agent, scoped to the folder you open.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 95 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to arsprengel/trail-mcp). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 3 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability59
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 3529 tokens (~196/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management80
- Stability observed for 24 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage76
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 27% of tool parameters carry a description.Partial
Tool Safety75
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 0 of 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "delete_item" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Fail
- An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Trail MCP server?
Trail runs locally as an npm package, launched with npx -y usetrail. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · usetrail
claude mcp add dev-usetrail-trail -- npx -y usetrail
{
"mcpServers": {
"dev-usetrail-trail": {
"command": "npx",
"args": [
"-y",
"usetrail"
]
}
}
} {
"servers": {
"dev-usetrail-trail": {
"command": "npx",
"args": [
"-y",
"usetrail"
]
}
}
} codex mcp add dev-usetrail-trail -- npx -y usetrail
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"dev-usetrail-trail": {
"type": "local",
"command": [
"npx",
"-y",
"usetrail"
],
"enabled": true
}
}
} openclaw mcp add dev-usetrail-trail --command npx --arg -y --arg usetrail
mcp_servers:
dev-usetrail-trail:
command: "npx"
args: ["-y", "usetrail"] {
"McpServers": {
"dev-usetrail-trail": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"usetrail"
]
}
}
} assistant mcp add dev-usetrail-trail -t stdio -c npx -a -y usetrail
{
"mcpServers": {
"dev-usetrail-trail": {
"command": "npx",
"args": [
"-y",
"usetrail"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 18 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 0
- Tool safety: pass → unverified ▼ security
- Stability: 0.63 → unverified ▼ security
- Capabilities: pass → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- First check of Schema quality: unverified functional
- Package version: 1.29.0 → 1.29.1 functional
- 16 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 60 to 63. That category is still filling its 30-day observation window: 18 days of observed history at the previous scan, 19 at this one. The score rises as the window fills, whether or not the server changes.
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 43 to 47. That category is still filling its 30-day observation window: 13 days of observed history at the previous scan, 14 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 37 to 40. That category is still filling its 30-day observation window: 11 days of observed history at the previous scan, 12 at this one. The score rises as the window fills, whether or not the server changes.
- 7 Sept 26 +16
- Malware scan: unverified → pass ▲ security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 21 Sept 2026 · Analysed npm/usetrail@1.29.1
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | arsprengel/trail-mcp |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/arsprengel/trail-mcp/.github/workflows/publish.yml@refs/heads/master |
| Rekor log index | 2880514595 |
| Predicate type | https://slsa.dev/provenance/v1 |
| Subject digest | sha512:3eba67fa1d2d8edd19cbe93a487b9335f916eafc786994b97fe79e45ba75d039958e026f8806446302c29fe9cc873e3f5f8801a4161695672f635c5d9 |
Background: How many MCP packages publish verified provenance →
Dependencies 95 packages
| Packages resolved | 95 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_attachment ~144
Anexa um arquivo (base64) a um card do tracker. Use pra guardar spec, doc ou planilha relevante ao card. Nasce INTERNO (so o time ve); passe shared_with_client=true pra o cliente do portal poder baixar. Default: projeto "workdir" (a pasta aberta); passe project so para outro.
| Name | Type | Req | Description |
|---|---|---|---|
| content_base64 | string | yes | conteudo do arquivo em base64 |
| description | string | – | resumo curto do anexo (a IA le isso na lista, barato) |
| filename | string | yes | – |
| item_id | string | yes | – |
| project | string | – | – |
| shared_with_client | boolean | – | – |
No output schema declared.
No examples provided.
add_item ~232
Cria um item (ponta solta). Chame ao descobrir trabalho novo a fazer. Default: projeto "workdir" (a pasta aberta); passe project so para outro.
| Name | Type | Req | Description |
|---|---|---|---|
| assignees | array | – | – |
| blocked_by | array | – | – |
| body | string | – | – |
| links | array | – | – |
| priority | string | – | – |
| project | string | – | – |
| status | string | – | – |
| summary | string | – | Resumo em portugues simples do que o CLIENTE precisa entender sobre este item: o que sera feito ou foi feito e por que isso importa pra ele. Sem jargao tecnico, sem nome de arquivo, sem nome de funca… |
| title | string | yes | – |
| type | string | – | – |
No output schema declared.
No examples provided.
add_memory ~459
Registra conhecimento duravel de REFERENCIA na MRP do projeto (comando, deploy, gotcha, decisao, contexto) - o que um agente precisa LER pra nao redescobrir. REGUA (as TRES precisam ser SIM; na duvida, NAO registre): (1) So vale NESTE projeto? Comportamento de linguagem, biblioteca ou ferramenta que se repete em qualquer projeto fica de fora - a IA ja sabe ou descobre numa busca. (2) Continua verdade daqui a 6 meses sem ninguem atualizar? Estado do dia, "agora"/"por enquanto", numero que muda e data de decisao recente ficam de fora. (3) Sem isso, a proxima sessao ERRA ou REFAZ trabalho? Vale armadilha E orientacao ("reuse o X, nao reinvente"); curiosidade nao vale. Grave so o PORQUE nao-obvio + a implicacao de futuro; NAO duplique SQL, constantes, estrutura de tabela nem passo-a-passo (isso vive no codigo/commit - no maximo aponte pra la). NAO registre trabalho-a-fazer/follow-up/backlog: isso e item do tracker (use add_item). Corte deliberado vira referencia com ponteiro pro item ("out-of-scope, ver #86"), nao TODO. Cheque list_memory antes para nao duplicar. Default: projeto "workdir" (a pasta aberta); passe project so para outro.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | – |
| category | string | yes | – |
| hint | string | yes | O GANCHO, uma linha: o que essa entrada poupa e QUANDO abri-la. Numa MRP grande e a UNICA coisa que o agente ve alem do titulo, entao e ele que decide se a entrada e lida. Escreva pra quem ainda nao… |
| project | string | – | – |
| title | string | yes | Curto (ate ~60 caracteres): o ASSUNTO, nao o resumo. Titulo longo e cortado na exibicao. |
No output schema declared.
No examples provided.
add_reminder ~170
Registra um lembrete/agendamento no Trail. Chame SEMPRE que prometer avisar algo no futuro ("quando chegar o dia X eu te lembro") ou combinar de retomar algo numa data - a sessao nao fica aberta pra lembrar sozinha; o Trail guarda e mostra no dashboard (aba Lembretes). Default: projeto "workdir" (a pasta aberta); passe project so para outro.
| Name | Type | Req | Description |
|---|---|---|---|
| item_id | string | – | id de um item do tracker a vincular (opcional) |
| message | string | yes | – |
| project | string | – | – |
| remind_at | string | yes | data/hora do lembrete em ISO 8601 (ex: 2026-08-01 ou 2026-08-01T09:00:00Z) |
No output schema declared.
No examples provided.
delete_item ~46
Apaga um item de vez (item + historico). Use quando um item foi criado por engano ou nao serve mais. Irreversivel.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
delete_reminder ~70
Apaga um lembrete de vez. Use so quando ele foi criado por engano ou com o projeto errado; pra encerrar um lembrete que cumpriu o papel, prefira update_reminder com status done (fica no historico). Irreversivel.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_attachment ~98
Le o CONTEUDO de um anexo sob demanda. IMAGEM VOLTA COMO IMAGEM DE VERDADE: se o card tem foto/print, CHAME AQUI e OLHE antes de perguntar ao usuario a que ele se refere. Texto extraido pra txt/csv. Nao chame a toa - a ficha dos anexos (nome, tipo, tamanho) ja vem no get_item.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_item ~128
Detalhe completo de um item por id. Chame antes de agir sobre um item para ver o estado atual. Traz junto a ficha dos ANEXOS do card (nome/tipo/tamanho): se houver imagem, abra com get_attachment(id) e OLHE - o print costuma ser o pedido inteiro. Se o item for type=idea (captura crua), clarifique o escopo com o usuario e entre em plan mode (plano para aprovar) antes de codar; feature/chore/bug detalhados podem ir direto.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_memory ~77
Le o CONTEUDO completo de UMA entrada da MRP por id (o body inteiro). Use pra abrir so a entrada relevante, a partir do indice do list_memory (ou dos titulos do inicio da sessao). Barato por design - nao puxe a MRP toda pra ler uma nota.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
get_next ~112
Retorna o proximo item aberto de maior prioridade, com a ficha dos anexos dele. Chame quando precisar decidir o que atacar a seguir. Default: projeto "workdir" (a pasta aberta); passe project so para outro. Se o item for type=idea (captura crua), clarifique o escopo com o usuario e entre em plan mode (plano para aprovar) antes de codar; feature/chore/bug detalhados podem ir direto.
| Name | Type | Req | Description |
|---|---|---|---|
| project | string | – | – |
No output schema declared.
No examples provided.
list_items ~254
Lista itens do tracker. Use no inicio para ver pontas abertas antes de agir. Filtre (status/type/tag) sempre que souber o que procura - e mais barato e mais preciso. Projeto grande: se a lista nao couber com os corpos, ela vem como INDICE de TODOS os itens (id/numero/titulo/tipo/status/prioridade), abertos primeiro, com aviso - nenhum item fica de fora, e o corpo de um item sai por get_item(id). Se ainda assim vier cortada, continue pelo proximo_cursor. Default: projeto "workdir" (a pasta aberta); passe project so para outro.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Continua de onde a resposta anterior parou. Use o proximo_cursor devolvido; e opaco, nao interprete o valor. |
| detail | string | – | full (padrao): itens completos, caindo pro indice sozinho se nao couber. index: pede logo o indice enxuto. |
| limit | integer | – | Teto de itens nesta resposta (o teto de tamanho vale de qualquer jeito). |
| project | string | – | – |
| status | string | – | – |
| tag | string | – | – |
| type | string | – | – |
No output schema declared.
No examples provided.
list_memory ~296
Le a MRP (Memoria Referencial de Projeto): comandos, deploy, gotchas, decisoes e contexto duraveis do projeto. Os TITULOS de todas as entradas ja vem no inicio da sessao. Por padrao devolve so o INDICE (id, categoria, titulo) - barato; use pra pegar os ids das entradas que interessam. Para o CONTEUDO: get_memory(id) le UMA entrada; list_memory({category, detail:"full"}) le os bodies de UMA categoria; detail:"full" sem category le TUDO (caro) - so quando precisar de varios bodies. Resposta grande demais vem PAGINADA: nesse caso vem um objeto com aviso/total/proximo_offset/entries - se proximo_offset nao for null, chame de novo com esse offset pra pegar o resto. SIGA o que estiver na MRP. Default: projeto "workdir" (a pasta aberta); passe project so para outro.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | – | – |
| detail | string | – | index (padrao): so id/categoria/titulo. full: bodies completos (combine com category pra escopar). |
| limit | integer | – | Teto de entradas nesta resposta (o teto de tamanho vale de qualquer jeito). |
| offset | integer | – | Pula as N primeiras entradas. Use o proximo_offset devolvido pela pagina anterior. |
| project | string | – | – |
No output schema declared.
No examples provided.
list_reminders ~96
Lista os lembretes/agendamentos do projeto, ordenados por data. Sem status vem TUDO (inclusive os ja fechados); passe status="pending" pra ver so o que ainda esta de pe. Chame pra conferir o que ja foi agendado. Default: projeto "workdir" (a pasta aberta); passe project so para outro.
| Name | Type | Req | Description |
|---|---|---|---|
| project | string | – | – |
| status | string | – | – |
No output schema declared.
No examples provided.
move_item ~60
Reordena um item na lista do seu projeto (index 0-based; 0 = topo, um numero grande = fim). Use para controlar a ordem/cronologia dos itens.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| index | integer | yes | – |
No output schema declared.
No examples provided.
review_memory ~230
FAXINA da MRP. Chame sem argumentos quando o inicio da sessao avisar que a faxina esta pendente (ou quando o usuario pedir limpeza): devolve um LOTE de entradas pra julgar, a regua e o que fazer. Depois chame de novo com keep/archive pra fechar a rodada. Existe porque a MRP so crescia: entrada boa e entrada morta ficavam lado a lado ate o indice virar parede de texto. O alvo e 80 entradas ativas por projeto - alvo desta faxina, nao trava do add_memory. Quem julga tem que ser a sessao que trabalha DENTRO do projeto: so ela consegue conferir se a nota ainda e verdade. Default: projeto "workdir" (a pasta aberta); passe project so para outro.
| Name | Type | Req | Description |
|---|---|---|---|
| archive | array | – | ids que SAEM da MRP. Arquiva (reversivel pelo dashboard), nunca apaga. |
| keep | array | – | ids que CONTINUAM valendo (so carimba o julgamento; nao mexe na entrada). |
| project | string | – | – |
No output schema declared.
No examples provided.
update_item ~160
Atualiza um item (status, notas, links). Chame ao concluir ou avancar trabalho. patch.summary: Resumo em portugues simples do que o CLIENTE precisa entender sobre este item: o que sera feito ou foi feito e por que isso importa pra ele. Sem jargao tecnico, sem nome de arquivo, sem nome de funcao, sem termo de implementacao. 2 a 3 frases, ate 600 caracteres. Preencha ao criar um item ja claro o suficiente para o cliente entender, ou ao concluir/avancar um item (junto da mudanca de status) - e o texto que aparece pro cliente no relatorio, em vez do corpo tecnico.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| patch | object | yes | – |
No output schema declared.
No examples provided.
update_memory ~47
Corrige uma entrada da MRP ou aposenta com patch {archived: true}. Prefira aposentar a apagar.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| patch | object | yes | – |
No output schema declared.
No examples provided.
update_reminder ~110
Muda um lembrete existente: FECHA ele (status done quando o assunto ja foi resolvido, dismissed quando nao vale mais), ADIA (remind_at novo) ou corrige a mensagem. Chame sempre que tratar um lembrete vencido - lembrete que ninguem fecha volta em toda abertura de sessao e vira ruido. Adiar tambem faz o aviso do vencimento sair de novo na data nova.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
| patch | object | yes | – |
No output schema declared.
No examples provided.
What is the Trail MCP server?
Trail is an MCP server listed in the public MCP registry as dev.usetrail/trail. Issue tracker and durable project memory for your coding agent, scoped to the folder you open. This page covers its npm package (usetrail).
Is the Trail MCP server safe to use?
Trail scores 85 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 21 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Trail MCP server expose?
Trail exposes 18 tools: list_items, get_item, add_item, update_item, move_item, and 13 more. Their descriptions and schemas cost roughly 2,789 tokens of context every time the server is loaded.
Is the Trail MCP server still maintained?
Trail is still listed as active in the MCP registry. We last reached this channel on 21 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Trail MCP server under?
Trail declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.