atlassian-mcp

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated Atlassian/MCP purpose is coherent, but the install and execution path is not: the skill recommends an npm package invocation that does not match the upstream project’s documented distribution, then forwards high-value Atlassian credentials into that third-party executable. This is disproportionate install-trust risk and weak data-flow integrity, even though the rest of the guidance is operationally reasonable.

Confidence: 92%Severity: 83%
Audit Metadata
Analyzed At
Aug 2, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/Krypton-Kr36%2Fclaude-code-skills%2Fatlassian-mcp%2F@accdd3bf7f9c4db0927d71ae1f3118abd3d3871d8251c8aec273b57b7ed95972
Security Audit — socket — atlassian-mcp