atlassian-mcp
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates workflows that ingest data from external, user-controlled sources (Jira issues and Confluence pages) which could be used to influence agent behavior.
- Ingestion points: The 'Triage Bot' and 'Documentation Sync' workflows in
references/common-workflows.mdfetch content usingjira_get_issueandconfluence_get_page. - Boundary markers: The provided implementation snippets do not include explicit instructions or delimiters to isolate untrusted content from the agent's primary instructions.
- Capability inventory: The skill scripts demonstrate capabilities to write back to the platform via
jira_update_issue,jira_add_comment, andconfluence_create_page. - Sanitization: While an
escapeHtmlutility is provided for formatting output, the logic lacks robust input validation or filtering for data retrieved from the Atlassian APIs before it is processed by the agent logic. - [SAFE]: The skill implements best practices for credential management and authentication.
- Evidence:
SKILL.mdcontains a 'MUST NOT DO' constraint regarding hardcoded API tokens.references/authentication-patterns.mdprovides comprehensive code examples for integrating with Google Cloud Secret Manager, AWS Secrets Manager, and HashiCorp Vault. - [SAFE]: External server configurations target established package registries and official sources.
- Evidence: Installation and setup instructions in
SKILL.mdandreferences/mcp-server-setup.mduse standardnpxanduvxcommands to fetch packages from public registries, including the official server from a trusted organization.
Audit Metadata