atlassian-mcp-server

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and Atlassian data flows are mostly coherent, and the prompt-injection and command-injection findings are low concern. The main issue is install/execution trust: it asks users to route Atlassian authentication through a third-party npm proxy that is not clearly published by Atlassian or the skill author, creating disproportionate credential-forwarding and supply-chain risk for an otherwise legitimate integration.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:32 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Fmcp-skills%2Fatlassian-mcp-server%2F@fd602440df6a1a961940435fd11ae85e3dd62963ff5fab5e0f7c7f794d3ce941
Security Audit — socket — atlassian-mcp-server