Atlas / MCP servers / matanyemini / Bitbucket

BitbucketSAFE

mcp/matanyemini/bitbucket-1

Bitbucket MCP - A Model Context Protocol (MCP) server for integrating with Bitbucket Cloud and Server APIs

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
49 27r · 19w · 3d
Transport
stdio · streamable-http
License
MIT
Stars
166
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for integrating with Bitbucket Cloud and Server APIs. This MCP server enables AI assistants like Cursor to interact with your Bitbucket repositories, pull requests, and other resources.

Safety First

This is a safe and responsible package — no DELETE operations are used, so there's no risk of data loss. Every pull request is analyzed with CodeQL to ensure the code remains secure.

[](https://github.com/MatanYemini/bitbucket-mcp/actions/workflows/github-code-scanning/codeql) [](https://github.com/MatanYemini/bitbucket-mcp) [](https://opensource.org/licenses/MIT) [](https://www.npmjs.com/package/bitbucket-mcp)

Overview

Checkout out the official npm package This server implements the Model Context Protocol standard to provide AI assistants with access to Bitbucket data and operations. It includes tools for:

  • Listing and retrieving repositories
  • Getting repository details
  • Fetching pull requests
  • And more...

Installation

-- Since it has been asked, in many cases we have seen - "BITBUCKET_USERNAME" is usually your email

Using NPX (Recommended)

The easiest way to use this MCP server is via NPX, which allows you to run it without installing it globally:

# Option A (recommended): API URL + explicit workspace
BITBUCKET_URL="https://api.bitbucket.org/2.0" \
BITBUCKET_WORKSPACE="your-workspace" \
BITBUCKET_USERNAME="your-username" \
BITBUCKET_PASSWORD="your-app-password" \
npx -y bitbucket-mcp@latest

# Option B (legacy-compatible): web URL only; workspace is auto-extracted
BITBUCKET_URL="https://bitbucket.org/your-workspace" \
BITBUCK
Read from source at commit 0ec68463430eOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add bitbucket-mcp -- npx -y [email protected]
03

Exposed tools (49)

27 read · 19 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
addPendingPullRequestCommentwriteAdd a pending (draft) comment to a pull request that can be published later
addPullRequestCommentwriteAdd a comment to a pull request (general, inline, or a threaded reply to another comment)
approvePullRequestreadApprove a pull request
convertTodraftreadConvert a regular pull request to draft status
createDraftPullRequestwriteCreate a new draft pull request
createPullRequestwriteCreate a new pull request
createPullRequestTaskwriteCreate a task on a pull request
declinePullRequestreadDecline a pull request
deletePullRequestCommentdestructiveDelete a comment on a pull request
deletePullRequestTaskdestructiveDelete a task from a pull request
getEffectiveDefaultReviewersreadGet effective default reviewers for a repository
getEffectiveRepositoryBranchingModelreadGet the effective branching model for a repository
getPendingReviewPRsreadList all open pull requests in the workspace where the authenticated user is a reviewer and has not yet approved.
getPipelineRunwriteGet details for a specific pipeline run
getPipelineStepreadGet details for a specific pipeline step
getPipelineStepLogsreadGet logs for a specific pipeline step
getPipelineStepswriteList steps for a pipeline run
getProjectBranchingModelreadGet the branching model for a project
getProjectBranchingModelSettingsreadGet the branching model config for a project
getPullRequestreadGet details for a specific pull request
getPullRequestActivityreadGet activity log for a pull request
getPullRequestCommentreadGet a specific comment on a pull request
getPullRequestCommentsreadList comments on a pull request
getPullRequestCommitsreadGet commits on a pull request
getPullRequestDiffreadGet diff for a pull request
getPullRequestDiffStatreadGet diff statistics for a pull request
getPullRequestPatchwriteGet patch for a pull request
getPullRequestStatuseswriteList commit statuses associated with a pull request
getPullRequestTaskreadGet a specific task on a pull request
getPullRequestTasksreadList tasks on a pull request
getPullRequestsreadGet pull requests for a repository
getRepositoryreadGet repository details
getRepositoryBranchingModelreadGet the branching model for a repository
getRepositoryBranchingModelSettingsreadGet the branching model config for a repository
listPipelineRunsreadList pipeline runs for a repository
listRepositoriesreadList Bitbucket repositories
mergePullRequestwriteMerge a pull request
publishDraftPullRequestwritePublish a draft pull request to make it ready for review
publishPendingCommentswritePublish all pending comments for a pull request
reopenCommentreadReopen a resolved comment thread on a pull request
resolveCommentreadResolve a comment thread on a pull request
runPipelinewriteTrigger a new pipeline run
stopPipelinewriteStop a running pipeline
unapprovePullRequestdestructiveRemove approval from a pull request
updateProjectBranchingModelSettingswriteUpdate the branching model config for a project
updatePullRequestwriteUpdate a pull request
updatePullRequestCommentwriteUpdate a comment on a pull request
updatePullRequestTaskwriteUpdate a task on a pull request
updateRepositoryBranchingModelSettingswriteUpdate the branching model config for a repository
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (5)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deletePullRequestComment, deletePullRequestTask, unapprovePullRequest
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
axios, dotenv, winston, @types/express, @types/jest, @types/node, @typescript-eslint/eslint-plugin, @typescript-eslint/parser
Why it matters. 15 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
CLAUDE.md:105
Requires "Pipelines: Read" permission in Bitbucket app password. Target configuration uses:
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:101
| `BITBUCKET_TOKEN`            | Your Bitbucket access token (alternative to username/password)                 | No       |
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
README.md:135
1. **Test API access**: Verify your credentials work by testing the Bitbucket API directly:
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 0ec68463430efull audit observations/trust-audit/mcp-server/matanyemini__bitbucket-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-070ec68463430eSAFEB89first audit
06

Questions

What is the Bitbucket MCP server?

Bitbucket MCP - A Model Context Protocol (MCP) server for integrating with Bitbucket Cloud and Server APIs

What tools does Bitbucket expose?

49 in total: 27 read-only, 19 that write, and 3 that can delete or overwrite (deletePullRequestComment, deletePullRequestTask, unapprovePullRequest). Every one is listed on this page with its risk.

Is Bitbucket safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Bitbucket need?

It reads BITBUCKET_PASSWORD and BITBUCKET_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Bitbucket run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as bitbucket-mcp at 5.0.7.

How current is this page?

The grade is for one exact copy of the source (0ec68463430e), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement