atlassian-with-mcporter

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent with Atlassian access, and the documented fallback targets official Atlassian APIs, but the skill’s footprint depends on a hardcoded local mcporter binary whose exact provenance cannot be verified from the skill itself. Because that external CLI likely handles Atlassian auth and may require unsandboxed local port binding, the trust and credential scope are higher than ideal for a read/verify skill.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
May 11, 2026, 03:16 PM
Package URL
pkg:socket/skills-sh/zereight%2Fskill%2Fatlassian-with-mcporter%2F@a2d533421cc84b5f2799e099a62d3a5fd754ad10