atlassian-mcp
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent, but its concrete configuration example points to an unofficial third-party MCP package via an install path that does not match the upstream project’s documented methods. That creates a meaningful supply-chain and credential-forwarding risk because Atlassian API tokens are handed to external code, even though the visible instructions do not show explicit exfiltration or malware behavior.
Confidence: 90%Severity: 78%
Audit Metadata