Atlas / MCP servers / lanbaoshen / Jenkins

JenkinsSAFE

mcp/lanbaoshen/jenkins-1

The Model Context Protocol (MCP) is an open-source implementation that bridges Jenkins with AI language models following Anthropic's MCP specification. This project enables secure, contextual AI interactions with Jenkins tools while maintaining data privacy and security.

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
35 30r · 5w · 0d
Transport
sse · stdio · streamable-http
License
MIT
Stars
154
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://pepy.tech/projects/mcp-jenkins) [](https://github.com/lanbaoshen/mcp-jenkins/actions/workflows/test.yml/badge.svg) [](https://codecov.io/gh/lanbaoshen/mcp-jenkins)

The Model Context Protocol (MCP) is an open-source implementation that bridges Jenkins with AI language models following Anthropic's MCP specification. This project enables secure, contextual AI interactions with Jenkins tools while maintaining data privacy and security.

Installation

Choose one of these installation methods:

# Using uv (recommended)
pip install uv
uvx mcp-jenkins

# Using pip
pip install mcp-jenkins
mcp-jenkins

# Docker
docker pull ghcr.io/lanbaoshen/mcp-jenkins:latest
docker run -p 9887:9887 --rm ghcr.io/lanbaoshen/mcp-jenkins:latest --transport streamable-http

Line Arguments

When using command line arguments, you can specify the Jenkins server details as follows:

# Simple streamable-http example
uvx mcp-jenkins --transport streamable-http
Read from source at commit 4d86196ad5a7OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add mcp-jenkins -- uvx mcp-jenkins
claude-desktop
{
  "mcpServers": {
    "mcp-jenkins": {
      "command": "uvx",
      "args": [
        "mcp-jenkins"
      ]
    }
  }
}
03

Exposed tools (35)

30 read · 5 write · 0 destructive.

ToolRiskDescription
build_itemreadBuild an item in Jenkins
cancel_queue_itemreadCancel a specific item in Jenkins queue by id
get_all_build_artifactsreadList the artifacts of a specific build in Jenkins
get_all_itemsreadGet all items from Jenkins
get_all_nodesreadGet all nodes from Jenkins
get_all_pluginsreadGet all installed plugins from Jenkins
get_all_queue_itemsreadGet all items in Jenkins queue
get_all_viewsreadGet all top-level views from Jenkins.
get_buildreadGet specific build info from Jenkins
get_build_artifactreadDownload an artifact from a specific build in Jenkins
get_build_artifact_urlreadGet the direct URL of an artifact from a specific build in Jenkins
get_build_console_outputreadGet the console output of a specific build in Jenkins
get_build_parametersreadGet the parameters of a specific build in Jenkins
get_build_scriptsreadGet the scripts used in a specific build in Jenkins
get_build_test_reportreadGet the test report of a specific build in Jenkins
get_itemreadGet specific item from Jenkins
get_item_configreadGet specific item config from Jenkins
get_item_parametersreadGet the parameter definitions of a Jenkins job
get_nodereadGet a specific node from Jenkins
get_node_configreadGet node config from Jenkins
get_pending_inputsreadGet the pending input steps of a specific build in Jenkins
get_pluginreadGet a specific plugin from Jenkins
get_plugin_dependency_graphreadGet dependency graph for a specific plugin in Graphviz format
get_plugins_with_backupreadGet plugins that can be downgraded
get_plugins_with_problemsreadGet all plugins with problems from Jenkins
get_plugins_with_updatesreadGet plugins that have available updates
get_queue_itemreadGet a specific item in Jenkins queue by id
get_running_buildsreadGet all running builds from Jenkins
get_viewreadGet a Jenkins view by path, returning its jobs and/or nested sub-views.
query_itemsreadQuery items from Jenkins
run_groovy_scriptwriteExecute an arbitrary Groovy script on Jenkins.
set_item_configwriteSet specific item config in Jenkins
set_node_configwriteSet specific node config in Jenkins
stop_buildwriteStop a specific build in Jenkins
submit_inputwriteRespond to a pipeline input step of a build that is paused for input in Jenkins
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (4)

LOWInventory / provenance · inv.hidden_file · CWE-1104
.gitmessage.txt
.gitmessage.txt
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
.pre-commit-config.yaml
.pre-commit-config.yaml
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWObfuscation / stealth · obf.decode_call · CWE-506, CWE-94
tests/test_server/test_build.py:498
assert base64.b64decode(result['content']) == bytes(range(256))
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:65
To load a `.env` file from a specific location, use `--env-file`:
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 4d86196ad5a7full audit observations/trust-audit/mcp-server/lanbaoshen__jenkins-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-074d86196ad5a7SAFEB89first audit
06

Questions

What is the Jenkins MCP server?

The Model Context Protocol (MCP) is an open-source implementation that bridges Jenkins with AI language models following Anthropic's MCP specification. This project enables secure, contextual AI interactions with Jenkins tools while maintaining data privacy and security.

What tools does Jenkins expose?

35 in total: 30 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Jenkins safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Jenkins need?

No credential environment variables were found in its source, so it appears to need none.

How does Jenkins run?

It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-jenkins.

How current is this page?

The grade is for one exact copy of the source (4d86196ad5a7), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement