atlassian-mcp

Warn

Audited by Socket on Jul 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is legitimate and its requested Atlassian credentials are proportionate, but its example setup routes those credentials through an unrelated third-party MCP server installed via unverified `npx` execution rather than Atlassian’s official MCP path. This is primarily a supply-chain and credential-forwarding risk, not confirmed malware.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Jul 29, 2026, 10:43 AM
Package URL
pkg:socket/skills-sh/nkseth%2Fcopilot-dev-skills%2Fatlassian-mcp%2F@9d25c92967fe6646c223a04ff0f75e39b9e6f2720f7c46966666546f71ac5991
Security Audit — socket — atlassian-mcp