Atlas / MCP servers / brianellin / Bluesky

BlueskySAFE

mcp/brianellin/bluesky-2

Bluesky MCP (Model Context Protocol) Server

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
21 17r · 4w · 0d
Transport
stdio
License
—
Stars
49
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://smithery.ai/server/@brianellin/bsky-mcp-server)

A Model Context Protocol server that connects to Bluesky and provides tools to interact with the ATProtocol.

You can use this MCP server to bring context from various Bluesky / ATProtocol API endpoints directly into the context window of your LLM based application. For example, you can add this server to Claude Desktop and then use it as a natural language Bluesky client.

Features & Tools

  • Interact with common Bluesky features via natural language (e.g. "Get recent posts from David Roberts")
  • Fetch and analyze feeds ("Find me a feed about Seattle and tell me what people are talking about")
  • Fetch and analyze lists of followers ("What types of accounts does Mark Cuban follow? Give me a detailed report")
  • Use an LLM to write a post and then post it for you 😱 ("Write a haiku about today's weather in my area and post it to bluesky")
  • Search for feeds, posts, and people ("Find posts about the #teslatakedown and give me a summary of recent events")
  • Analyze who follows you? ("Who follows me on Bluesky? Give me a report")

Here's the current list of tools provided:

  • get-pinned-feeds: returns the set of all "pinned" items from the authenticated user's preferences.
  • get-timeline-posts: returns posts from the authenticated user's home timeline
  • get-feed-posts: returns posts from the specified feed
  • get-list-posts: returns posts from the specified list
  • get-user-posts: returns the specified user's posts
  • get-profile: returns the profile details of the specified user
  • get-follows: returns the set of users an account follows
  • get-followers: returns the set of users who follow an account
  • get-liked-posts: returns recent posts liked by the authenticated user
  • get-trends: returns current trending topics on Blues
Read from source at commit 19970ccd1a51OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add bsky-mcp-server --env BLUESKY_APP_PASSWORD=${BLUESKY_APP_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "bsky-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "BLUESKY_APP_PASSWORD": "${BLUESKY_APP_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (21)

17 read · 4 write · 0 destructive.

ToolRiskDescription
convert-url-to-urireadConvert a Bluesky web URL to an AT URI format that can be used with other tools
create-postwriteCreate a new post on Bluesky
follow-userreadFollow a user on Bluesky
get-feed-postsreadFetch posts from a specified feed
get-followersreadGet a list of users that follow a person
get-followsreadGet a list of users that a person follows
get-liked-postsreadGet a list of posts that the authenticated user has liked
get-list-postsreadFetch posts from users in a specified list
get-my-handle-and-didreadReturn the handle and did of the currently authenticated user for this blusesky session. Useful for when someone asks information about themselves using
get-pinned-feedsreadGet the authenticated user
get-post-likeswriteGet information about users who have liked a specific post
get-post-threadwriteGet a full conversation thread for a specific post, showing replies and context
get-profilereadGet a user
get-timeline-postsreadFetch your home timeline from Bluesky, which includes posts from all of the people you follow in reverse chronological order
get-trendsreadGet current trending topics on Bluesky
get-user-postsreadFetch posts from a specific user
like-postwriteLike a post on Bluesky
list-resourcesreadList all available MCP resources with their descriptions
search-feedsreadSearch for custom feeds on Bluesky
search-peoplereadSearch for users/actors on Bluesky
search-postsreadSearch for posts on Bluesky
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/tools/test-get-post-thread.ts:253
const outputDir = path.join(__dirname, '../../test/output');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
test/url-converter/test-url-converter.ts:1
import { parseBskyUrl } from '../../src/utils.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@atproto/api, @modelcontextprotocol/sdk, date-fns, dotenv, zod, @types/node, ts-node, typescript
Why it matters. 8 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
README.md:110
- This server stores your session information in memory only and does not share it with the MCP client.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-08 · audit v0.4.1 · source sha 19970ccd1a51full audit observations/trust-audit/mcp-server/brianellin__bluesky-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0819970ccd1a51SAFEB89first audit
06

Questions

What is the Bluesky MCP server?

Bluesky MCP (Model Context Protocol) Server

What tools does Bluesky expose?

21 in total: 17 read-only, 4 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Bluesky safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Bluesky need?

It reads BLUESKY_APP_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Bluesky run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as bsky-mcp-server at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (19970ccd1a51), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement