atlassian-mcp

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation URL https://jeffallan.github.io/claude-skills/skills/platform/atlassian-mcp/ referenced in SKILL.md has been flagged as malicious by automated scanners.
  • [REMOTE_CODE_EXECUTION]: The skill recommends executing third-party packages via npx -y @sooperset/mcp-atlassian, which downloads and runs external code at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The automated workflows in references/common-workflows.md ingest untrusted data from Jira issues and Confluence pages to perform write operations without boundary markers or sanitization.
  • Ingestion points: jira_get_issue and confluence_get_page are used to pull external content.
  • Boundary markers: No delimiters or instructions are used to separate user data from agent instructions.
  • Capability inventory: The skill has permissions to create issues, add comments, and update wiki pages.
  • Sanitization: The skill logic lacks filtering for malicious instructions embedded in the external content.
  • [METADATA_POISONING]: The file SKILL.md is flagged for malicious reputation by scanners, and there is a discrepancy between the stated author Jeffallan and the environment author sodiqabdulwaris.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:38 AM
Security Audit — agent-trust-hub — atlassian-mcp