atlassian-mcp

Warn

Audited by Socket on Sep 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent, but its concrete configuration example points to an unofficial third-party MCP package via an install path that does not match the upstream project’s documented methods. That creates a meaningful supply-chain and credential-forwarding risk because Atlassian API tokens are handed to external code, even though the visible instructions do not show explicit exfiltration or malware behavior.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Sep 13, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/1git2clone%2Fdotfiles%2Fatlassian-mcp%2F@9ddb613af79d9baeef18fe3114367422c47cc3e23cb5e638cb67375fa530a235
Security Audit — socket — atlassian-mcp