> For the complete documentation index, see [llms.txt](https://support.attackforge.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.attackforge.com/app/modules/ai-mcp-and-skills/find-project-test-cases.md).

# Find Project Test Cases

#### Description <a href="#description" id="description"></a>

Lists the test cases allocated to one AttackForge project. A project test case is a per-project instance of a library test case - it carries the testing state for that project: `status`, who it is `assigned_to`, which project scope items it covers, which vulnerabilities it uncovered, and whether it is `locked`.

It does **not** carry the descriptive fields (`title`, `details`, `code`, `tags`): those live on the parent library test case. Take `testcase_id` from these results and pass it to `find_testcases` via its `testcase_ids` parameter to resolve them.

The caller must have access to the project's test cases. Results are paginated (default 10 per page, max 50). See Test Cases and Methodology.

#### How To Enable <a href="#how-to-enable" id="how-to-enable"></a>

1. Go to `Users`
2. Select the user you would like to provide access to this tool
3. Click on `Access > MCP`
4. Click on `Add Tools`
5. Select the tool `find_project_testcases` and click `Add`

#### Example Prompts <a href="#example-prompts" id="example-prompts"></a>

* *Show me the test cases for project X and their statuses.*
* *Which test cases in project X are still not tested?*
* *What test cases are assigned to me on the ACME project?*
* *Show me the test cases in project X that are unassigned.*
* *Which test cases uncovered vulnerabilities in this project?*
* *Which scope items does each test case in project X cover?*
* *List the locked test cases on this project.*

#### Parameters <a href="#parameters" id="parameters"></a>

| Parameter           | Type    | Required | Description                                                                                                                                                    |
| ------------------- | ------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `project_id`        | string  | Yes      | Id (24-hex) of the project whose test cases you want to list. Source: `find_projects`. The caller must have access to this project's test cases.               |
| `filter`            | object  | No       | A MongoDB-style filter. Supported fields are listed below.                                                                                                     |
| `fields`            | array   | No       | System fields to include (`id` is always returned). Supported values are listed below.                                                                         |
| `custom_field_keys` | array   | No       | Custom field keys to include (discover via `get_field_structure(model="project-testcase")` - these are distinct from the custom fields on library test cases). |
| `limit`             | integer | No       | Maximum records to return in this page. Default 10, max 50.                                                                                                    |
| `skip`              | integer | No       | Number of records to skip (offset). Default 0.                                                                                                                 |

**Supported `filter` fields:**

| Field                 | Type / Values                                                                  |
| --------------------- | ------------------------------------------------------------------------------ |
| `id`                  | `ObjectId('<24 hex>')` - the project test case id                              |
| `created`, `modified` | ISO-8601 datetime                                                              |
| `status`              | one of `'Tested'`, `'Not Tested'`, `'Testing In Progress'`, `'Not Applicable'` |
| `assigned_to`         | `ObjectId('<24 hex>')` - the user the test case is assigned to                 |
| `locked`              | boolean - supports `$eq`, `$ne` and `$exists` only                             |
| `custom_fields`       | array of `{ key: string, value: string or array }`                             |
| `testcase_id`         | `ObjectId('<24 hex>')` - the parent library test case                          |
| `user_id`             | `ObjectId('<24 hex>')`                                                         |

> Disallowed inside `filter`: `project_id` (use the parameter), and `title`, `details`, `code`, `tags`, `sort_order`, `testsuite_id` - these live on the parent library test case. To narrow by them, call `find_testcases` first and filter on the resulting `testcase_id` values.

**Supported `fields` values:**

| Field                 | Type                                                                                             |
| --------------------- | ------------------------------------------------------------------------------------------------ |
| `id`                  | string                                                                                           |
| `created`, `modified` | ISO-8601 datetime                                                                                |
| `status`              | one of `'Tested'`, `'Not Tested'`, `'Testing In Progress'`, `'Not Applicable'`                   |
| `assigned_to`         | string                                                                                           |
| `project_scope_ids`   | array of string                                                                                  |
| `locked`              | boolean                                                                                          |
| `files`               | array of `{ id, created, modified, name, mimeType, hash, size, storage_name, storage_location }` |
| `testcase_id`         | string                                                                                           |
| `user_id`             | string                                                                                           |
| `vulnerability_ids`   | array of string                                                                                  |

#### Example Response

```json
{
  "data": [
    {
      "id": "6987c31b8e7d46a8089d9b54",
      "created": "2026-01-30T04:18:11.402Z",
      "modified": "2026-03-11T15:22:47.118Z",
      "status": "Tested",
      "assigned_to": "5ad737d6e576e6290aff1808",
      "project_scope_ids": [
        "66a440c08cade68ca7bc7192"
      ],
      "locked": false,
      "testcase_id": "65a440c08cade68ca7bc71a4",
      "user_id": "5ad737d6e576e6290aff1808",
      "vulnerability_ids": [
        "656168055d7035a12ade4cb3"
      ],
      "custom_fields": [
        {
          "key": "testing_effort",
          "value": "2h",
          "label": "Testing Effort"
        }
      ]
    }
  ],
  "count": 1,
  "total": 86
}
```


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://support.attackforge.com/app/modules/ai-mcp-and-skills/find-project-test-cases.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
