BacklogSAFE
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://mcptoplist.com/server/glama%2Fnulab%2Fbacklog-mcp-server)
📘 日本語でのご利用ガイド
A Model Context Protocol (MCP) server for interacting with the Backlog API. This server provides tools for managing projects, issues, wiki pages, and more in Backlog through AI agents like Claude Desktop / Cline / Cursor etc.
Features
- Project tools (create, read, update, delete)
- Issue tracking and comments (create, update, delete, list)
- Version/Milestone management (create, read, update, delete)
- Wiki page support
- Git repository and pull request tools
- Notification tools
- Field selection for optimized responses
- Token limiting for large responses
Getting Started
Requirements
- Docker
- A Backlog account with API access
- API key from your Backlog account
Option 1: Install via Docker
The easiest way to use this MCP server is through MCP configurations:
- Open MCP settings
- Navigate to the MCP configuration section
- Add the following configuration:
{
"mcpServers": {
"backlog": {
"command": "docker",
"args": [
"run",
"--pull",
"always",
"-i",
"--rm",
"-e",
"BACKLOG_DOMAIN",
"-e",
"BACKLOG_API_KEY",
"ghcr.io/nulab/backlog-mcp-server"
],
"env": {
"BACKLOG_DOMAIN": "your-domain.backlog.com",
"BACKLOG_API_KEY": "your-api-key"
}
}
}
}Replace your-domain.backlog.com with your Backlog domain and your-api-key with your Backlog API key.
✅ If you cannot use --pull always, you can manually update the image using:
docker pull ghcr.io/nulab/
53b90cbd96a6OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add backlog-mcp-server -- npx -y [email protected]
{
"mcpServers": {
"backlog-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (16)
15 read · 1 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
CF1 | read | |
CF2 | read | Desc |
another-repo | read | Another repository |
document | read | Tools for managing documents. |
dummy | read | dummy |
get_sample | read | Returns sample |
git | read | Tools for managing Git repositories and pull requests. |
issue | read | Tools for managing issues and their comments. |
notifications | read | Tools for managing user notifications. |
organization_metadata | read | Tools for inspecting configured Backlog organizations. |
project | read | Tools for managing projects, categories, custom fields, and issue types. |
space | read | Tools for managing Backlog space settings and general information. |
test-repo | read | Test repository |
v1.0.0 | read | First release |
v1.1.0 | write | Minor update |
wiki | read | Tools for managing wiki pages. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (11)
import { getCurrentOrganization } from '../../utils/backlogOrganizationContext.js';import { NativeContentToolDefinition } from '../../types/tool.js';import { ErrorLike, isErrorLike } from '../../types/result.js';import { NativeContentToolDefinition } from '../../types/tool.js';import { ErrorLike } from '../../types/result.js';(`http://localhost`、`http://127.0.0.1`、`http://[::1]`)はユーザーのマシン上で動く
URI (`http://localhost`, `http://127.0.0.1`, `http://[::1]`) is how an app running
'http://127.0.0.1:8888/callback',
@hono/node-server, @modelcontextprotocol/hono, @modelcontextprotocol/server, backlog-js, env-var, hono, js-yaml, pino
- **Protocol:** MCP `2026-07-28`. The protocol is stateless: there is no `initialize` handshake and no `mcp-session-id` header. Clients send their metadata in `_meta` on every request and discover cap
| `POST /token` | Token endpoint (authorization code & refresh token) |
Gates applied: no_behavioural_pass.
53b90cbd96a6full audit observations/trust-audit/mcp-server/nulab__backlog-4.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 53b90cbd96a6 | SAFE | B | 89 | first audit |
Questions
What tools does Backlog expose?
16 in total: 15 read-only, 1 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Backlog safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Backlog need?
No credential environment variables were found in its source, so it appears to need none.
How current is this page?
The grade is for one exact copy of the source (53b90cbd96a6), read on 2026-10-06. The repository is watched and re-audited when it changes.