Atlassian JiraSAFE
Node.js/TypeScript MCP server for Atlassian Jira. Equips AI systems (LLMs) with tools to list/get projects, search/get issues (using JQL/ID), and view dev info (commits, PRs). Connects AI capabilities directly into Jira project management and issue tracking workflows.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Transform how you manage and track your work by connecting Claude, Cursor AI, and other AI assistants directly to your Jira projects, issues, and workflows. Get instant project insights, streamline issue management, and enhance your team collaboration.
[](https://www.npmjs.com/package/@aashari/mcp-server-atlassian-jira)
What You Can Do
- Ask AI about your projects: "What are the active issues in the DEV project?"
- Get issue insights: "Show me details about PROJ-123 including comments"
- Track project progress: "List all high priority issues assigned to me"
- Manage issue comments: "Add a comment to PROJ-456 about the test results"
- Search across projects: "Find all bugs in progress across my projects"
- Create and update issues: "Create a new bug in the MOBILE project"
Perfect For
- Developers who need quick access to issue details and development context
- Project Managers tracking progress, priorities, and team assignments
- Scrum Masters managing sprints and workflow states
- Team Leads monitoring project health and issue resolution
- QA Engineers tracking bugs and testing status
- Anyone who wants to interact with Jira using natural language
Quick Start
Get up and running in 2 minutes:
1. Get Your Jira Credentials
Generate a Jira API Token:
- Go to Atlassian API Tokens
- Click Create API token
- Give it a name like "AI Assistant"
- Copy the generated token immediately (you won't see it again!)
2. Try It Instantly
# Set your credentials export ATLASSIAN_SITE_NAME="your-company" # for your-company.atlassian.net export ATLASSIAN_USER_EMAIL="[email protected]" export ATLASSIAN_API_TOKEN="your_api_token" # List your Jira projects npx -y @aashari/mcp-server-atlassian-jira get --path "/r
fb68e9d3980fOBSERVED · 2026-10-07Exposed tools (5)
1 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
jira_delete | destructive | |
jira_get | read | |
jira_patch | write | |
jira_post | write | |
jira_put | write |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (8)
jira_delete
.node-version
.releaserc.json
.trigger-ci
@modelcontextprotocol/sdk, @toon-format/toon, commander, cors, dotenv, express, jmespath, turndown
- Full access to any Jira REST API endpoint
- Full access to any Jira REST API v3 endpoint (not just predefined tools)
Gates applied: no_behavioural_pass, no_license.
fb68e9d3980ffull audit observations/trust-audit/mcp-server/aashari__atlassian-jira.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | fb68e9d3980f | SAFE | B | 89 | first audit |
Questions
What is the Atlassian Jira MCP server?
Node.js/TypeScript MCP server for Atlassian Jira. Equips AI systems (LLMs) with tools to list/get projects, search/get issues (using JQL/ID), and view dev info (commits, PRs). Connects AI capabilities directly into Jira project management and issue tracking workflows.
What tools does Atlassian Jira expose?
5 in total: 1 read-only, 3 that write, and 1 that can delete or overwrite (jira_delete). Every one is listed on this page with its risk.
Is Atlassian Jira safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Atlassian Jira need?
It reads ATLASSIAN_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Atlassian Jira run?
It speaks stdio and streamable-http, so it runs as a local process your client starts.
How current is this page?
The grade is for one exact copy of the source (fb68e9d3980f), read on 2026-10-07. The repository is watched and re-audited when it changes.