atlassian-mcp

Warn

Audited by Socket on Aug 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The business purpose is coherent, but the trust chain is not. The skill directs users to run a non-official third-party MCP server from a different publisher and forward Atlassian credentials into it, with install guidance that does not clearly match the upstream project’s primary documented methods.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Aug 23, 2026, 07:57 AM
Package URL
pkg:socket/skills-sh/polip%2Fopencode-skills%2Fatlassian-mcp%2F@9ddb613af79d9baeef18fe3114367422c47cc3e23cb5e638cb67375fa530a235
Security Audit — socket — atlassian-mcp