atlassian-mcp
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation URL https://jeffallan.github.io/claude-skills/skills/platform/atlassian-mcp/ referenced in SKILL.md has been flagged as malicious by automated scanners.
- [REMOTE_CODE_EXECUTION]: The skill recommends executing third-party packages via npx -y @sooperset/mcp-atlassian, which downloads and runs external code at runtime.
- [INDIRECT_PROMPT_INJECTION]: The automated workflows in references/common-workflows.md ingest untrusted data from Jira issues and Confluence pages to perform write operations without boundary markers or sanitization.
- Ingestion points: jira_get_issue and confluence_get_page are used to pull external content.
- Boundary markers: No delimiters or instructions are used to separate user data from agent instructions.
- Capability inventory: The skill has permissions to create issues, add comments, and update wiki pages.
- Sanitization: The skill logic lacks filtering for malicious instructions embedded in the external content.
- [METADATA_POISONING]: The file SKILL.md is flagged for malicious reputation by scanners, and there is a discrepancy between the stated author Jeffallan and the environment author sodiqabdulwaris.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata