atlassian-mcp
Warn
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill configuration examples in
SKILL.mdandreferences/mcp-server-setup.mdrecommend the use of community-maintained packages such as@sooperset/mcp-atlassianandatlassian-mcp(by xuanxt). These are hosted on public registries and executed vianpxoruvxwithout version pinning or integrity verification. - [COMMAND_EXECUTION]: The skill provides configuration templates that use shell commands (
npx -y,uvx) to dynamically download and execute MCP server code. While intended for setup, this pattern facilitates the execution of remote code from unverified sources. - [PROMPT_INJECTION]: The automated workflows in
references/common-workflows.md(specifically the Triage Bot and Documentation Sync) represent an indirect prompt injection surface. - Ingestion points: The
triageNewIssuefunction reads thesummaryanddescriptionof Jira issues, andsyncMeetingNotesreads the full XHTML content of Confluence pages. - Boundary markers: The logic does not employ delimiters or system instructions to prevent the agent from following commands that might be embedded within the ticket or page content being processed.
- Capability inventory: The skill has broad capabilities including
jira_create_issue,jira_add_comment, andconfluence_update_page, allowing injected instructions to trigger unauthorized write operations. - Sanitization: While HTML escaping is used for Confluence storage format output, there is no validation or sanitization of the incoming natural language data before it influences categorization and tool call arguments.
Audit Metadata