atlassian-mcp

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill configuration examples in SKILL.md and references/mcp-server-setup.md recommend the use of community-maintained packages such as @sooperset/mcp-atlassian and atlassian-mcp (by xuanxt). These are hosted on public registries and executed via npx or uvx without version pinning or integrity verification.
  • [COMMAND_EXECUTION]: The skill provides configuration templates that use shell commands (npx -y, uvx) to dynamically download and execute MCP server code. While intended for setup, this pattern facilitates the execution of remote code from unverified sources.
  • [PROMPT_INJECTION]: The automated workflows in references/common-workflows.md (specifically the Triage Bot and Documentation Sync) represent an indirect prompt injection surface.
  • Ingestion points: The triageNewIssue function reads the summary and description of Jira issues, and syncMeetingNotes reads the full XHTML content of Confluence pages.
  • Boundary markers: The logic does not employ delimiters or system instructions to prevent the agent from following commands that might be embedded within the ticket or page content being processed.
  • Capability inventory: The skill has broad capabilities including jira_create_issue, jira_add_comment, and confluence_update_page, allowing injected instructions to trigger unauthorized write operations.
  • Sanitization: While HTML escaping is used for Confluence storage format output, there is no validation or sanitization of the incoming natural language data before it influences categorization and tool call arguments.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 08:51 PM
Security Audit — agent-trust-hub — atlassian-mcp