JenkinsSAFE
The Model Context Protocol (MCP) is an open-source implementation that bridges Jenkins with AI language models following Anthropic's MCP specification. This project enables secure, contextual AI interactions with Jenkins tools while maintaining data privacy and security.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://pepy.tech/projects/mcp-jenkins) [](https://github.com/lanbaoshen/mcp-jenkins/actions/workflows/test.yml/badge.svg) [](https://codecov.io/gh/lanbaoshen/mcp-jenkins)
The Model Context Protocol (MCP) is an open-source implementation that bridges Jenkins with AI language models following Anthropic's MCP specification. This project enables secure, contextual AI interactions with Jenkins tools while maintaining data privacy and security.
Installation
Choose one of these installation methods:
# Using uv (recommended) pip install uv uvx mcp-jenkins # Using pip pip install mcp-jenkins mcp-jenkins # Docker docker pull ghcr.io/lanbaoshen/mcp-jenkins:latest docker run -p 9887:9887 --rm ghcr.io/lanbaoshen/mcp-jenkins:latest --transport streamable-http
Line Arguments
When using command line arguments, you can specify the Jenkins server details as follows:
# Simple streamable-http example uvx mcp-jenkins --transport streamable-http
4d86196ad5a7OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add mcp-jenkins -- uvx mcp-jenkins
{
"mcpServers": {
"mcp-jenkins": {
"command": "uvx",
"args": [
"mcp-jenkins"
]
}
}
}Exposed tools (35)
30 read · 5 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
build_item | read | Build an item in Jenkins |
cancel_queue_item | read | Cancel a specific item in Jenkins queue by id |
get_all_build_artifacts | read | List the artifacts of a specific build in Jenkins |
get_all_items | read | Get all items from Jenkins |
get_all_nodes | read | Get all nodes from Jenkins |
get_all_plugins | read | Get all installed plugins from Jenkins |
get_all_queue_items | read | Get all items in Jenkins queue |
get_all_views | read | Get all top-level views from Jenkins. |
get_build | read | Get specific build info from Jenkins |
get_build_artifact | read | Download an artifact from a specific build in Jenkins |
get_build_artifact_url | read | Get the direct URL of an artifact from a specific build in Jenkins |
get_build_console_output | read | Get the console output of a specific build in Jenkins |
get_build_parameters | read | Get the parameters of a specific build in Jenkins |
get_build_scripts | read | Get the scripts used in a specific build in Jenkins |
get_build_test_report | read | Get the test report of a specific build in Jenkins |
get_item | read | Get specific item from Jenkins |
get_item_config | read | Get specific item config from Jenkins |
get_item_parameters | read | Get the parameter definitions of a Jenkins job |
get_node | read | Get a specific node from Jenkins |
get_node_config | read | Get node config from Jenkins |
get_pending_inputs | read | Get the pending input steps of a specific build in Jenkins |
get_plugin | read | Get a specific plugin from Jenkins |
get_plugin_dependency_graph | read | Get dependency graph for a specific plugin in Graphviz format |
get_plugins_with_backup | read | Get plugins that can be downgraded |
get_plugins_with_problems | read | Get all plugins with problems from Jenkins |
get_plugins_with_updates | read | Get plugins that have available updates |
get_queue_item | read | Get a specific item in Jenkins queue by id |
get_running_builds | read | Get all running builds from Jenkins |
get_view | read | Get a Jenkins view by path, returning its jobs and/or nested sub-views. |
query_items | read | Query items from Jenkins |
run_groovy_script | write | Execute an arbitrary Groovy script on Jenkins. |
set_item_config | write | Set specific item config in Jenkins |
set_node_config | write | Set specific node config in Jenkins |
stop_build | write | Stop a specific build in Jenkins |
submit_input | write | Respond to a pipeline input step of a build that is paused for input in Jenkins |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (4)
.gitmessage.txt
.pre-commit-config.yaml
assert base64.b64decode(result['content']) == bytes(range(256))
To load a `.env` file from a specific location, use `--env-file`:
Gates applied: no_behavioural_pass.
4d86196ad5a7full audit observations/trust-audit/mcp-server/lanbaoshen__jenkins-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 4d86196ad5a7 | SAFE | B | 89 | first audit |
Questions
What is the Jenkins MCP server?
The Model Context Protocol (MCP) is an open-source implementation that bridges Jenkins with AI language models following Anthropic's MCP specification. This project enables secure, contextual AI interactions with Jenkins tools while maintaining data privacy and security.
What tools does Jenkins expose?
35 in total: 30 read-only, 5 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Jenkins safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Jenkins need?
No credential environment variables were found in its source, so it appears to need none.
How does Jenkins run?
It speaks sse, stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as mcp-jenkins.
How current is this page?
The grade is for one exact copy of the source (4d86196ad5a7), read on 2026-10-07. The repository is watched and re-audited when it changes.