atlassian-mcp

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is legitimate and its requested Atlassian credentials are proportionate, but its example setup routes those credentials through an unrelated third-party MCP server installed via unverified `npx` execution rather than Atlassian’s official MCP path. This is primarily a supply-chain and credential-forwarding risk, not confirmed malware.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Aug 2, 2026, 03:58 PM
Package URL
pkg:socket/skills-sh/hosseinmirzapur%2Fopencode-skills%2Fatlassian-mcp%2F@503afb2735b574d3a2f44256d0c6d79feb760f3da8099865c782210d8143a32f
Security Audit — socket — atlassian-mcp