atlassian-mcp-server
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's purpose and Atlassian data flows are mostly coherent, and the prompt-injection and command-injection findings are low concern. The main issue is install/execution trust: it asks users to route Atlassian authentication through a third-party npm proxy that is not clearly published by Atlassian or the skill author, creating disproportionate credential-forwarding and supply-chain risk for an otherwise legitimate integration.
Confidence: 88%Severity: 64%
Audit Metadata