atlassian-mcp

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes automated workflows (Triage Bot, Documentation Sync) that process untrusted data from Jira and Confluence.
  • Ingestion points: The skill fetches Jira issue fields (summary, description, comments) and Confluence page content in references/common-workflows.md.
  • Boundary markers: The processing logic lacks explicit delimiters or instructions to ignore embedded instructions within the fetched text.
  • Capability inventory: The skill utilizes tools to write to the workspace (jira_update_issue, confluence_update_page), allowing malicious data in an issue or page to potentially influence automated decisions or modifications.
  • Sanitization: While basic HTML escaping is used for Confluence page creation, no semantic filtering is applied to the input text.
  • [EXTERNAL_DOWNLOADS]: The skill recommends third-party MCP servers from community maintainers.
  • Evidence: Recommends @sooperset/mcp-atlassian and atlassian-mcp (xuanxt) in references/mcp-server-setup.md.
  • [REMOTE_CODE_EXECUTION]: Configuration patterns involve downloading and executing code from public registries at runtime.
  • Evidence: Recommends configuration using npx -y @sooperset/mcp-atlassian and uvx mcp-atlassian to execute MCP servers on demand.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — atlassian-mcp