atlassian-mcp

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates workflows that ingest data from external, user-controlled sources (Jira issues and Confluence pages) which could be used to influence agent behavior.
  • Ingestion points: The 'Triage Bot' and 'Documentation Sync' workflows in references/common-workflows.md fetch content using jira_get_issue and confluence_get_page.
  • Boundary markers: The provided implementation snippets do not include explicit instructions or delimiters to isolate untrusted content from the agent's primary instructions.
  • Capability inventory: The skill scripts demonstrate capabilities to write back to the platform via jira_update_issue, jira_add_comment, and confluence_create_page.
  • Sanitization: While an escapeHtml utility is provided for formatting output, the logic lacks robust input validation or filtering for data retrieved from the Atlassian APIs before it is processed by the agent logic.
  • [SAFE]: The skill implements best practices for credential management and authentication.
  • Evidence: SKILL.md contains a 'MUST NOT DO' constraint regarding hardcoded API tokens. references/authentication-patterns.md provides comprehensive code examples for integrating with Google Cloud Secret Manager, AWS Secrets Manager, and HashiCorp Vault.
  • [SAFE]: External server configurations target established package registries and official sources.
  • Evidence: Installation and setup instructions in SKILL.md and references/mcp-server-setup.md use standard npx and uvx commands to fetch packages from public registries, including the official server from a trusted organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — atlassian-mcp