{"generated_at":"2026-09-18T12:54:00+00:00","item":{"added_at":"2026-07-28","analysis_method":"capability_triage","category":"Web Connector","description":"Manage CI/CD pipelines, debug failed builds, and optimize test suites directly from Claude - no terminal required.","did":"09103c21-59c7-480e-8fb4-69914bfa311e","homepage_url":"https://circleci.com/","icon":"","id":"09103c21-59c7-480e-8fb4-69914bfa311e","installs":0,"last_scanned":"","license":"","long_description":"The CircleCI MCP Server is a remote server hosted by CircleCI that connects Claude directly to your CI/CD pipelines, giving you a conversational interface to the same pipeline, workflow, job, and artifact data you'd normally reach through the CircleCI CLI or dashboard.\n\nWith this connector, you can ask Claude to check the latest pipeline status for a project or roll back a deployment - all without leaving your conversation. When something breaks, Claude can pull the failure logs for a specific build and help you understand what went wrong, or dig into test results for a job to pinpoint which tests failed and why.\n\nBeyond troubleshooting individual runs, the server supports broader pipeline health and efficiency work. Claude can  identify underused resource classes to help you right-size compute and control costs, and list artifacts produced by your builds so you can retrieve build outputs without hunting through the UI.\n\nIt also helps with day-to-day project management: checking component versions across your fleet, and pulling usage data for cost and consumption analysis. For configuration work, it can act as a config helper - assisting with validating and troubleshooting your .circleci/config.yml setup.\n\nIn short, this MCP Server turns Claude into a working partner for CI/CD: monitoring pipeline health, debugging build and test failures, managing releases and rollbacks, and keeping an eye on cost and reliability - all through natural conversation rather than manual dashboard digging or CLI commands.","name":"CircleCI","plutonium_url":"https://plutonium.pluto.security/detail.html?planet=claudesec&did=09103c21-59c7-480e-8fb4-69914bfa311e&utm_source=plutonium_analysis_skill&utm_medium=claude_skill&utm_campaign=connector_risk_assessment","publisher":"CircleCI Engineering","publisher_url":"https://circleci.com/","repository_url":"","risk":"high","risk_severity":"high","security_risks":[{"description":"This connector can execute scripts, shell commands, or arbitrary database queries. In a worst case, an attacker could install software, read files, or pull or change any data its login can reach.","evidence":"1 observed tool(s): rollback_deploy_component.","remediation":{"block_tool_categories":["code_execution"],"steps":["In the tools list below, turn off any tool tagged Block before connecting this to real data or production systems.","If you need code execution, run it on a separate test machine that has no access to your work files, customer data, or saved passwords.","Limit which websites and services that test machine can talk to."]},"risk_type":"runs_code","severity":"high","title":"Can run commands or queries on your behalf"},{"description":"This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.","evidence":"19 observed tool(s): get_deploy_component, get_deploy_environment, get_job, get_job_logs, get_job_resource_usage, get_me, ….","remediation":{"block_tool_categories":[],"steps":["Connect using an account that only has access to the information you actually want Claude to read - not your main admin login.","When you grant access, pick the smallest set of folders, mailboxes, or channels possible.","Check the connector's activity log every so often to make sure nothing unexpected is being read."]},"risk_type":"reads_private_data","severity":"low","title":"Reads your private information"},{"description":"Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.","evidence":"1 observed tool(s): [remote publisher endpoint].","remediation":{"block_tool_categories":[],"steps":["Treat anything you tell this connector as if you sent it directly to the third-party company - because you did.","Check how long that company keeps your data and how to delete it.","Avoid putting health info, customer names, or payment details into this connector unless you have a written agreement with that company."]},"risk_type":"forwards_data_to_third_party","severity":"low","title":"Sends your data to outside companies"}],"signature_status":"unknown","source_code_reviewed":false,"tags":["code_deployment","forwards_data_to_third_party","network_access","reads_private_data","runs_code","web_connector"],"tools":[{"description":"","name":"cancel_workflow"},{"description":"","name":"download_usage_data"},{"description":"","name":"get_deploy_component"},{"description":"","name":"get_deploy_environment"},{"description":"","name":"get_job"},{"description":"","name":"get_job_logs"},{"description":"","name":"get_job_resource_usage"},{"description":"","name":"get_me"},{"description":"","name":"get_orb"},{"description":"","name":"get_orb_source"},{"description":"","name":"get_run"},{"description":"","name":"get_workflow"},{"description":"","name":"list_deploy_component_versions"},{"description":"","name":"list_deploy_components"},{"description":"","name":"list_deploy_environments"},{"description":"","name":"list_deployments"},{"description":"","name":"list_job_artifacts"},{"description":"","name":"list_job_tests"},{"description":"","name":"list_run_workflows"},{"description":"","name":"list_runs"},{"description":"","name":"list_workflow_jobs"},{"description":"","name":"rerun_workflow"},{"description":"","name":"rollback_deploy_component","risk":{"category":"code_execution","level":"high","recommendation":"Block in production. If needed, scope tightly to a sandboxed account and require explicit approval.","why":"Runs arbitrary code, queries, shell commands, or deployment actions with the privileges granted to the connector."}},{"description":"","name":"validate_config"}],"tools_count":24,"type":"web_connector","url":"https://claude.ai/directory/09103c21-59c7-480e-8fb4-69914bfa311e","uuid":"6e45b5d3-79cc-5eee-b726-56284e140e87","version":""},"query_key":"circleci","schema_version":1,"status":"match"}
