Bitbucket Python Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Bitbucket Python Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Model Context Protocol (MCP) server for BitBucket Cloud operations. This server enables AI coding agents like Claude Code CLI and Codex CLI to interact with BitBucket repositories, branches, and pull requests.
uvx bitbucket-python-mcppip install bitbucket-python-mcpgit clone https://github.com/yourusername/bitbucket-python-mcp.git
cd bitbucket-python-mcp
uv syncThe server requires the following environment variables:
| Variable | Required | Description |
|---|---|---|
BITBUCKET_USERNAME | Yes | Your BitBucket username (not email) |
BITBUCKET_API_TOKEN | Yes | App password/API token from BitBucket settings |
BITBUCKET_WORKSPACE | Yes | Default workspace slug |
BITBUCKET_MCP_DEBUG | No | Enable debug logging (1/true/yes) |
Add to your ~/.claude/claude_desktop_config.json:
{
"mcpServers": {
"bitbucket": {
"command": "uvx",
"args": ["bitbucket-python-mcp"],
"env": {
"BITBUCKET_USERNAME": "your-username",
"BITBUCKET_API_TOKEN": "your-api-token",
"BITBUCKET_WORKSPACE": "your-workspace"
}
}
}
}Add to your ~/.codex/config.toml:
[mcp_servers.bitbucket]
command = "uvx"
args = ["bitbucket-python-mcp"]
[mcp_servers.bitbucket.env]
BITBUCKET_USERNAME = "your-username"
BITBUCKET_API_TOKEN = "your-api-token"
BITBUCKET_WORKSPACE = "your-workspace"Alternatively, use the Codex CLI to add the server:
codex mcp add bitbucket \
--env BITBUCKET_USERNAME=your-username \
--env BITBUCKET_API_TOKEN=your-api-token \
--env BITBUCKET_WORKSPACE=your-workspace \
-- uvx bitbucket-python-mcpVerify the server is configured:
codex mcp list# Set environment variables
export BITBUCKET_USERNAME="your-username"
export BITBUCKET_API_TOKEN="your-api-token"
export BITBUCKET_WORKSPACE="your-workspace"
# Run the server
uvx bitbucket-python-mcp
# or
uv run bitbucket-python-mcp| Tool | Description |
|---|---|
list_repositories | List all repositories in a workspace |
get_repository | Get detailed repository information |
create_repository | Create a new repository |
delete_repository | Delete a repository (requires confirmation) |
update_repository | Update repository settings |
| Tool | Description |
|---|---|
list_branches | List all branches in a repository |
get_branch | Get branch details |
create_branch | Create a new branch |
delete_branch | Delete a branch (requires confirmation) |
| Tool | Description |
|---|---|
list_pull_requests | List pull requests (open/merged/declined) |
get_pull_request | Get PR details (defaults to newest) |
get_pull_request_diff | Get the diff for a PR |
get_pull_request_comments | Get all comments on a PR |
add_pull_request_comment | Add a comment (general or inline) |
approve_pull_request | Approve a PR |
request_changes | Request changes on a PR |
create_pull_request | Create a new PR |
| Tool | Description |
|---|---|
search_repositories | Search for repositories by name |
get_repository_contents | Browse repository files/directories |
search_code | Search for code patterns |
get_file_content | Get raw file content |
| Tool | Description |
|---|---|
add_memory | Store a new learning/standard for future reference |
list_memories | List stored memories filtered by workspace/category |
search_memories | Search memories by keyword |
get_relevant_memories | Get memories relevant to current context |
delete_memory | Delete a stored memory |
remember_from_pr_comment | Extract and store learning from a PR comment |
Memories are stored in ~/.bitbucket-python-mcp/memory/ and persist across sessions.
User: Create a new private repository named "my-new-project" with description "My awesome project"User: Create a new branch named "feature-login" from developmentUser: Show me the details of the newest pull request
User: What are the comments on PR #42?
User: Approve PR #42User: Search for "authentication" in the project-api repository
User: Show me the contents of src/main.pyUser: Remember that we should use shared-pipeline for SonarQube scans
User: What standards should I follow for this workspace?
User: Search memories for "pipeline"# Clone the repository
git clone https://github.com/yourusername/bitbucket-python-mcp.git
cd bitbucket-python-mcp
# Install dependencies
uv sync --all-extras
# or using just
just install-devuv run pytest
# or using just
just testuv run ruff check src tests
uv run ruff format src tests
# or using just
just fmt
just lintuv build
# or using just
just buildContributions are welcome! Please feel free to submit a Pull Request.
git checkout -b feature/amazing-feature)git commit -m 'Add some amazing feature')git push origin feature/amazing-feature)This project is licensed under the MIT License - see the LICENSE file for details.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.