atlassian-mcp
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes automated workflows (Triage Bot, Documentation Sync) that process untrusted data from Jira and Confluence.
- Ingestion points: The skill fetches Jira issue fields (summary, description, comments) and Confluence page content in
references/common-workflows.md. - Boundary markers: The processing logic lacks explicit delimiters or instructions to ignore embedded instructions within the fetched text.
- Capability inventory: The skill utilizes tools to write to the workspace (
jira_update_issue,confluence_update_page), allowing malicious data in an issue or page to potentially influence automated decisions or modifications. - Sanitization: While basic HTML escaping is used for Confluence page creation, no semantic filtering is applied to the input text.
- [EXTERNAL_DOWNLOADS]: The skill recommends third-party MCP servers from community maintainers.
- Evidence: Recommends
@sooperset/mcp-atlassianandatlassian-mcp(xuanxt) inreferences/mcp-server-setup.md. - [REMOTE_CODE_EXECUTION]: Configuration patterns involve downloading and executing code from public registries at runtime.
- Evidence: Recommends configuration using
npx -y @sooperset/mcp-atlassiananduvx mcp-atlassianto execute MCP servers on demand.
Audit Metadata