atlassian-setup
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose and Atlassian-focused data flows are mostly coherent, but it relies on a third-party `mcp-remote` proxy installed via unpinned `npx @latest`, and that proxy participates in OAuth/token handling. This is not confirmed malware, but it creates meaningful supply-chain and credential-forwarding risk beyond what an official first-party connector would require.
Confidence: 89%Severity: 68%
Audit Metadata