No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by buildkite · MCP Server · ★ 54
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is buildkite-mcp-server safe to install? View the security audit →
buildkite-mcp-server Model Context Protocol (MCP) server exposing Buildkite data (pipelines, builds, jobs, tests) to AI tooling and editors. Full documentation is available at buildkite.com/docs/apis/mcp-server. Library Usage The exported Go API of this module should be considered unstable, and subject to breaking changes as we evolve this project. Security To ensure the MCP server is run in a secure environment, we recommend running it in a container. This image is built from cgr.dev/chainguard/static and runs as an unprivileged user. Contributing Development guidelines are in . License MIT © Buildkite SPDX-License-Identifier: MIT
| Stars | 54 |
| Forks | 38 |
| Language | Go |
| Category | MCP Server |
| License | MIT |
| Quality Score | 56.253393204496/100 |
| Open Issues | 26 |
| Last Updated | 2026-09-22 |
| Created | 2025-04-08 |
| Platforms | go, mcp |
| Est. Tokens | ~15k |
These tools work well together with buildkite-mcp-server for enhanced workflows:
Explore other popular mcp server tools:
buildkite-mcp-server is Official MCP Server for Buildkite.. It is categorized as a MCP Server with 54 GitHub stars.
buildkite-mcp-server is primarily written in Go. It covers topics such as buildkite, mcp-server.
You can find installation instructions and usage details in the buildkite-mcp-server GitHub repository at github.com/buildkite/buildkite-mcp-server. The project has 54 stars and 38 forks, indicating an active community.
buildkite-mcp-server is released under the MIT license, making it free to use and modify according to the license terms.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: