atlassian-setup

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and Atlassian-focused data flows are mostly coherent, but it relies on a third-party `mcp-remote` proxy installed via unpinned `npx @latest`, and that proxy participates in OAuth/token handling. This is not confirmed malware, but it creates meaningful supply-chain and credential-forwarding risk beyond what an official first-party connector would require.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
May 16, 2026, 07:15 PM
Package URL
pkg:socket/skills-sh/davekilleen%2FDex%2Fatlassian-setup%2F@2b7a86d44356f0afc6289720e7b14a7e26637369
Security Audit — socket — atlassian-setup