backlot — security grade SAFE, quality 66/100

Security audit verdict: SAFE · quality 66/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by brekkylab · MCP Server · ★ 216

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is backlot safe to install? View the security audit →

About backlot

Backlot Run enterprise SaaS APIs locally. Backlot is a local emulator for Slack, Gmail, Google Drive, GitHub, Jira, Notion, S3 and other enterprise APIs. It reproduces the response shapes, pagination, authentication, errors and per-document access controls an integration has to handle, over a deterministic corpus you control — so you build and test against the official vendor SDKs with no vendor account, no OAuth approval, no secrets in CI and no network. ![Connecting Slack to an app, two ways, side by side. On the left, the real Slack API: create a workspace, register an app, add a bot user, pick OAuth scopes, register a redirect URL, install to the workspace — then wait on an admin to approve it, with still zero API calls made. On the right, Backlot: pip install, backlot serve, and one changed base URL, after which a conversations.history r

ai-agentsamazon-s3api-mockenterprisefastapigithubgmailgoogle-drivejiramcp

Quick Facts

Stars216
Forks18
LanguagePython
CategoryMCP Server
LicenseMIT
Quality Score66.108432432595/100
Open Issues18
Last Updated2026-09-20
Created2026-07-02
Platformsmcp, python
Est. Tokens~15k

backlot alternative? Top 6 similar tools

Looking for a backlot alternative? If you're comparing backlot with other mcp server tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • 10xProductivity by ZhixiangLuo · ⭐ 471

    Personal AI assistant for work inside corporate constraints, built on coding agents and the tools, sessions, a

  • corpusos by Corpus-OS · ⭐ 213

    Open-source protocol suite standardizing LLM, Vector, Graph, and Embedding infrastructure across LangChain, Ll

  • OpenDocuments by joungminsung · ⭐ 103

    Self-hosted RAG platform for AI document search across GitHub, Notion, Google Drive, local files, and web sour

  • orchestkit by yonatangross · ⭐ 278

    The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install `ork` for stabl

  • enterprise-mcp-course by decodingai-magazine · ⭐ 272

    Learn to build from scratch an AI PR reviewer integrated with GitHub, Slack and Asana that scales within your

  • omnicoreagent by omnirexflora-labs · ⭐ 246

    Open Python agent harness for production AI apps: tools, MCP, memory, workspace, telemetry, subagents, backgro

More MCP Server Tools

Explore other popular mcp server tools:

View all MCP Server tools →

Popular Python Agent Tools

Frequently Asked Questions

What is backlot?

backlot is A local emulator for enterprise SaaS APIs — Slack, Gmail, Google Drive, GitHub, Jira, Notion, S3 and more — with the real response shapes, pagination, auth and per-document ACLs, over a corpus you sup. It is categorized as a MCP Server with 216 GitHub stars.

What programming language is backlot written in?

backlot is primarily written in Python. It covers topics such as ai-agents, amazon-s3, api-mock.

How do I install or use backlot?

You can find installation instructions and usage details in the backlot GitHub repository at github.com/brekkylab/backlot. The project has 216 stars and 18 forks, indicating an active community.

What license does backlot use?

backlot is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to backlot?

The top alternatives to backlot on Agent Skills Hub include 10xProductivity, corpusos, OpenDocuments. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse MCP Server tools