Atlas / MCP servers / pdogra1299 / Bitbucket

BitbucketSAFE

mcp/pdogra1299/bitbucket-2

MCP Server for interacting with BitBucket API

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
25 13r · 9w · 3d
Transport
stdio
License
MIT
Stars
29
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/@nexus2520/bitbucket-mcp-server) [](https://opensource.org/licenses/MIT)

MCP server for Bitbucket — built for AI coding agents that need to work with remote repositories as if they were local clones: grep-fast code search, windowed file reads, compact token-efficient responses, and a transport layer that never trips Bitbucket's rate limits.

Supports Bitbucket Server / Data Center (primary target) and Bitbucket Cloud.

Why v3

Measured on a live Data Center instance: a repeated content search went from 519 API calls / ~7s (finding 1 of 8 real matches under burst throttling) to 0 API calls / 24ms finding all 8. Full design and verified API research: REVAMP_PLAN.md.

Tools (25)

Search (search) — Server/DC only

  • `grep` — search file contents with full regex, any branch, like ripgrep on a local clone. One archive download per repo+commit, streamed in constant memory, cached in-process, freshness-checked every call (responses carry as_of ). Omit query for filename-only glob listing. Modes: content, files, count; glob, path, context, case_insensitive, max_results.
  • `search_code` — index-bac
Read from source at commit a41f606bb86aOBSERVED · 2026-10-09
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.

claude-code
claude mcp add bitbucket-mcp-server -- npx -y @nexus2520/[email protected]
claude-desktop
{
  "mcpServers": {
    "bitbucket-mcp-server": {
      "command": "npx",
      "args": [
        "-y",
        "@nexus2520/[email protected]"
      ]
    }
  }
}
03

Exposed tools (25)

13 read · 9 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
add_commentwriteAdd a PR comment: general, threaded reply (parent_comment_id), inline (file_path + line_number),
create_pull_requestwriteCreate a pull request.
decline_pull_requestreadDecline a pull request, optionally with a comment. Pass
delete_branchdestructiveDelete a branch. Pass expected_head (commit SHA) to skip the lookup call (Server).
get_branchwriteGet a branch with its latest commit and open PRs (include_merged_prs adds merged ones).
get_commit_detailwriteGet a commit diff as raw unified diff text, or detail:
get_file_blamewritePer-line blame as commit spans (one call per ≤5000-line window — pass start_line/line_count for big files).
get_file_contentreadRead a file. Windowed by default (start_line/line_count fetch ONLY that window server-side; ≤5000 lines per call).
get_pull_requestwriteGet a pull request: metadata, reviewer status, merge info, comments and changed files.
get_pull_request_diffreadGet a PR diff as raw unified diff text (line numbers derive from @@ headers; +/- prefixes mark ADDED/REMOVED).
grepreadSearch file CONTENTS in a repo with full regex, like ripgrep on a local clone — any branch, no index gaps.
list_branch_commitsreadList commits on a branch. since (as a rev) and include_merge_commits filter server-side;
list_branchesreadList branches (most recently modified first on Server).
list_directory_contentreadList files and directories at a repository path.
list_pr_commitsreadList commits in a pull request.
list_projectsreadList accessible projects/workspaces.
list_pull_requestsreadList pull requests in a repository. Omit
list_repositoriesreadList repositories in a project (or all accessible on Server).
manage_attachmentsdestructiveDownload or delete a repository attachment by numeric id (Server only). Upload via the attachments param on add_comment/create_pull_request/update_pull_request. No list API exists.
manage_commentdestructiveEdit/delete/resolve/reopen a PR comment or task, or convert between comment and task (to_task/to_comment are Server-only).
merge_pull_requestwriteMerge a pull request. Pass
search_codereadIndex-backed exact-term code search across a whole PROJECT in one call (default branch only, files <512KiB,
search_repositoriesreadFind repositories by name/description across the instance. Server only.
set_review_statuswriteSet YOUR reviewer status on a PR: APPROVED, NEEDS_WORK (request changes), or UNAPPROVED (clear).
update_pull_requestwriteUpdate a pull request. Reviewers/approvals are preserved unless
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (4 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete_branch, manage_attachments, manage_comment
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.releaserc.json
.releaserc.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
memory-bank/.clinerules
.clinerules
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInsecure crypto · crypto.weak_hash · CWE-327, CWE-338
src/core/snapshot.ts:515
return createHash('sha1').update(buf).digest('hex');
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, form-data, tar-stream, @semantic-release/changelog, @semantic-release/git, @types/minimatch, @types/node
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
SETUP_GUIDE.md:64
Once you have these credentials, share them with me and I'll configure the MCP server for you. The credentials will be stored securely in your MCP settings configuration.
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SETUP_GUIDE_SERVER.md:3
Since you're using Bitbucket Server (self-hosted), you'll need to create an HTTP access token instead of an app password.
Why it matters. asks the agent to read credentials
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
SETUP_GUIDE_SERVER.md:57
2. An HTTP access token from the "HTTP access tokens" section
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha a41f606bb86afull audit observations/trust-audit/mcp-server/pdogra1299__bitbucket-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-09a41f606bb86aSAFEB89first audit
06

Questions

What is the Bitbucket MCP server?

MCP Server for interacting with BitBucket API

What tools does Bitbucket expose?

25 in total: 13 read-only, 9 that write, and 3 that can delete or overwrite (delete_branch, manage_attachments, manage_comment). Every one is listed on this page with its risk.

Is Bitbucket safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Bitbucket need?

No credential environment variables were found in its source, so it appears to need none.

How does Bitbucket run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @nexus2520/bitbucket-mcp-server at 3.0.1.

How current is this page?

The grade is for one exact copy of the source (a41f606bb86a), read on 2026-10-09. The repository is watched and re-audited when it changes.

Advertisement