BlueskySAFE
Bluesky MCP (Model Context Protocol) Server
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://smithery.ai/server/@brianellin/bsky-mcp-server)
A Model Context Protocol server that connects to Bluesky and provides tools to interact with the ATProtocol.
You can use this MCP server to bring context from various Bluesky / ATProtocol API endpoints directly into the context window of your LLM based application. For example, you can add this server to Claude Desktop and then use it as a natural language Bluesky client.
Features & Tools
- Interact with common Bluesky features via natural language (e.g. "Get recent posts from David Roberts")
- Fetch and analyze feeds ("Find me a feed about Seattle and tell me what people are talking about")
- Fetch and analyze lists of followers ("What types of accounts does Mark Cuban follow? Give me a detailed report")
- Use an LLM to write a post and then post it for you 😱 ("Write a haiku about today's weather in my area and post it to bluesky")
- Search for feeds, posts, and people ("Find posts about the #teslatakedown and give me a summary of recent events")
- Analyze who follows you? ("Who follows me on Bluesky? Give me a report")
Here's the current list of tools provided:
- get-pinned-feeds: returns the set of all "pinned" items from the authenticated user's preferences.
- get-timeline-posts: returns posts from the authenticated user's home timeline
- get-feed-posts: returns posts from the specified feed
- get-list-posts: returns posts from the specified list
- get-user-posts: returns the specified user's posts
- get-profile: returns the profile details of the specified user
- get-follows: returns the set of users an account follows
- get-followers: returns the set of users who follow an account
- get-liked-posts: returns recent posts liked by the authenticated user
- get-trends: returns current trending topics on Blues
19970ccd1a51OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add bsky-mcp-server --env BLUESKY_APP_PASSWORD=${BLUESKY_APP_PASSWORD} -- npx -y [email protected]{
"mcpServers": {
"bsky-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"BLUESKY_APP_PASSWORD": "${BLUESKY_APP_PASSWORD}"
}
}
}
}Exposed tools (21)
17 read · 4 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
convert-url-to-uri | read | Convert a Bluesky web URL to an AT URI format that can be used with other tools |
create-post | write | Create a new post on Bluesky |
follow-user | read | Follow a user on Bluesky |
get-feed-posts | read | Fetch posts from a specified feed |
get-followers | read | Get a list of users that follow a person |
get-follows | read | Get a list of users that a person follows |
get-liked-posts | read | Get a list of posts that the authenticated user has liked |
get-list-posts | read | Fetch posts from users in a specified list |
get-my-handle-and-did | read | Return the handle and did of the currently authenticated user for this blusesky session. Useful for when someone asks information about themselves using |
get-pinned-feeds | read | Get the authenticated user |
get-post-likes | write | Get information about users who have liked a specific post |
get-post-thread | write | Get a full conversation thread for a specific post, showing replies and context |
get-profile | read | Get a user |
get-timeline-posts | read | Fetch your home timeline from Bluesky, which includes posts from all of the people you follow in reverse chronological order |
get-trends | read | Get current trending topics on Bluesky |
get-user-posts | read | Fetch posts from a specific user |
like-post | write | Like a post on Bluesky |
list-resources | read | List all available MCP resources with their descriptions |
search-feeds | read | Search for custom feeds on Bluesky |
search-people | read | Search for users/actors on Bluesky |
search-posts | read | Search for posts on Bluesky |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
const outputDir = path.join(__dirname, '../../test/output');
import { parseBskyUrl } from '../../src/utils.js';@atproto/api, @modelcontextprotocol/sdk, date-fns, dotenv, zod, @types/node, ts-node, typescript
- This server stores your session information in memory only and does not share it with the MCP client.
Gates applied: no_behavioural_pass, no_license.
19970ccd1a51full audit observations/trust-audit/mcp-server/brianellin__bluesky-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 19970ccd1a51 | SAFE | B | 89 | first audit |
Questions
What is the Bluesky MCP server?
Bluesky MCP (Model Context Protocol) Server
What tools does Bluesky expose?
21 in total: 17 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Bluesky safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Bluesky need?
It reads BLUESKY_APP_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Bluesky run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as bsky-mcp-server at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (19970ccd1a51), read on 2026-10-08. The repository is watched and re-audited when it changes.