Atlas / MCP servers / b1ff / Atlassian Data Center

Atlassian Data CenterCAUTION

mcp/b1ff/atlassian-data-center

MCP servers for the Atlassian products (Bitbucket, Confluence, JIRA) of the Data Center version

Verdict
CAUTION
Grade
C
Trust score
79 /100
Exposed tools
51 33r · 16w · 2d
Transport
sse · stdio
License
MIT
Stars
102
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://mseep.ai/app/b1ff-atlassian-dc-mcp)

[](https://mseep.ai/app/2a87ecc6-e53a-4a21-b63e-ede9b6a2bc4a)

Note: This is a community-maintained project and is not affiliated with, endorsed by, or supported by Atlassian. Use at your own discretion.

This project provides a Model Context Protocol (MCP) integration for Atlassian Data Center products, including Jira, Confluence, and Bitbucket.

Quick Setup

Each package ships an interactive setup subcommand that stores your credentials in the most secure place available on your OS. Run it once per product:

npx @atlassian-dc-mcp/jira setup
npx @atlassian-dc-mcp/confluence setup
npx @atlassian-dc-mcp/bitbucket setup

The setup CLI prompts for host, API base path, default page size, and API token. Before saving, it validates obvious input mistakes and performs a timed authenticated request to the selected Atlassian product, so a bad host, base path, or token is caught during setup.

CLI flags and non-interactive mode

Setup accepts flags so you can prefill values or skip prompts entirely (useful for scripted bootstrap, CI, or remote sessions). Run npx @atlassian-dc-mcp/ setup --help for the full list.

In interactive mode, any flag you pass prefills its prompt (so e.g. --host skips the host prompt but still asks for the rest). In --non-interactive mode, setup resolves anything

Read from source at commit 8b5cac96ae81OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (npm)
claude mcp add bitbucket --env BITBUCKET_API_TOKEN=${BITBUCKET_API_TOKEN} -- npx -y @atlassian-dc-mcp/[email protected]
03

Exposed tools (51)

33 read · 16 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
bitbucket_canMergePullRequestreadCheck whether a pull request can be merged. Read-only: returns canMerge, whether the pull request is conflicted, and any merge-check vetoes (e.g. missing approvals, unresolved tasks, failed builds). Use this before bitbucket_mergePullRequest to see what is blocking a merge.
bitbucket_createBranchwriteCreate a branch in a Bitbucket repository, forked from a branch, tag or commit. Use this before bitbucket_createPullRequest when the source branch does not exist yet. The response contains the new branch
bitbucket_createPullRequestread
bitbucket_declinePullRequestreadDecline (close without merging) a pull request. IMPORTANT: you MUST first call bitbucket_getPullRequest to get the current
bitbucket_getBranchDiffreadGet the diff between two branches, tags or commits — including branches that have no pull request yet. Returns the same comparison as the Bitbucket
bitbucket_getCommitsreadGet commits for a Bitbucket repository
bitbucket_getDashboardPullRequestsreadGet pull requests from the Bitbucket dashboard across all repositories. Useful for finding all PRs where you are the author, reviewer, or participant without specifying a project or repository.
bitbucket_getFileContentreadGet the raw content of a file in a Bitbucket repository, at a branch, tag or commit. Use this to read a source file without cloning the repository.
bitbucket_getInboxPullRequestsreadGet pull requests from the authenticated user
bitbucket_getPR_CommentsAndActionreadGet comments for a Bitbucket pull request and other actions, like approvals
bitbucket_getProjectreadGet a specific Bitbucket project by key
bitbucket_getProjectsreadGet a list of Bitbucket projects
bitbucket_getPullRequestreadGet a specific pull request by ID. Returns full details including title, description, reviewers, participants, author, source/target branches, current state, and version (needed for bitbucket_updatePullRequest).
bitbucket_getPullRequestChangesreadGet the changes for a Bitbucket pull request
bitbucket_getPullRequestDiffreadGet text diff for a specific file in a Bitbucket pull request. Returns plain text diff format. Note: Before getting diff, use getPullRequestChanges to understand what files were changed in the PR
bitbucket_getPullRequestsreadGet pull requests for a Bitbucket repository
bitbucket_getRepositoriesreadGet repositories for a Bitbucket project
bitbucket_getRepositoryreadGet a specific Bitbucket repository
bitbucket_getRequiredReviewerswriteGet required reviewers for pull request creation. Returns a set of users who are required reviewers for pull requests created from the given source repository and ref to the given target ref in this repository.
bitbucket_getUserreadGet a Bitbucket user by their slug, or search for users by name/email to discover their slug. Use this to resolve userSlug for bitbucket_submitPullRequestReview when it is not already known from a comment response or PR participant list.
bitbucket_mergePullRequestwriteMerge a pull request. IMPORTANT: you MUST first call bitbucket_getPullRequest to get the current
bitbucket_postPullRequestCommentread
bitbucket_reopenPullRequestreadReopen a declined pull request, restoring it to OPEN. IMPORTANT: you MUST first call bitbucket_getPullRequest to get the current
bitbucket_searchCodereadSearch code across Bitbucket. The query supports search modifiers like
bitbucket_submitPullRequestReviewwriteSubmit a pull request review, publishing all pending (draft) comments and setting the reviewer
bitbucket_updatePullRequestwriteUpdate the title, description, reviewers, destination branch or draft status of an existing pull request. IMPORTANT: You MUST first call bitbucket_getPullRequest to get the current
bitbucket_updatePullRequestCommentwriteUpdate an existing pull request comment. Use to edit text, change severity, change task state, or resolve/reopen the comment thread. On a BLOCKER (task) comment, state:
confluence_createContentwriteCreate new content in ${confluenceInstanceType}
confluence_downloadAttachmentreadDownload one or more attachments from a Confluence content (page) in the ${confluenceInstanceType}. Returns the file content inline (base64 or text). Useful for inspecting a file or moving it elsewhere (e.g. re-uploading to a Jira issue).${downloadSaveEnabled ?
confluence_getContentreadGet Confluence content by ID from the ${confluenceInstanceType}
confluence_searchContentreadSearch for content in ${confluenceInstanceType} using CQL
confluence_searchSpacereadSearch for spaces in ${confluenceInstanceType}
confluence_updateContentwriteUpdate existing content in ${confluenceInstanceType}. Optionally move the page by setting parentId.
confluence_uploadAttachmentwriteUpload a local file as an attachment to a Confluence content (page) in the ${confluenceInstanceType}. The file must live under the server-configured upload directory; the path is given relative to that directory.
jira_createIssuewriteCreate a new JIRA issue in the ${jiraInstanceType}
jira_downloadAttachmentread
jira_getIssuereadGet details of a JIRA issue by its key from the ${jiraInstanceType}
jira_getIssueCommentsreadGet comments of a JIRA issue by its key from the ${jiraInstanceType}
jira_getIssueDevelopmentInforeadGet linked development information (pull requests, commits, or branches) shown in the Development panel of a JIRA issue in the ${jiraInstanceType}. Defaults to pull requests from Bitbucket.
jira_getIssueLinkTypesreadGet the list of available issue link types (e.g. Blocks, Relates, Duplicate) in the ${jiraInstanceType}. Use this to discover valid link type names before calling jira_linkIssues.
jira_getTransitionsreadGet available status transitions for a JIRA issue in the ${jiraInstanceType}. Returns a list of transitions with their IDs, names, and target statuses.
jira_linkIssueswriteCreate a link between two JIRA issues in the ${jiraInstanceType}. Direction is easy to invert vs the Jira UI: inwardIssueKey is the issue that DISPLAYS the outward phrase (e.g.
jira_postIssueCommentwritePost a comment on a JIRA issue in the ${jiraInstanceType}
jira_searchIssuesreadSearch for JIRA issues using JQL in the ${jiraInstanceType}
jira_transitionIssuereadTransition a JIRA issue to a new status in the ${jiraInstanceType}. Use jira_getTransitions first to get available transition IDs.
jira_unlinkIssuesdestructiveDelete an existing link between two JIRA issues in the ${jiraInstanceType}. Requires the issue link id (found in the
jira_unwatchIssuedestructiveRemove yourself (the authenticated user) as a watcher from a JIRA issue in the ${jiraInstanceType}. Only the calling user can be removed; there is no way to unwatch on behalf of someone else.
jira_updateIssuewriteUpdate an existing JIRA issue in the ${jiraInstanceType}
jira_updateIssueCommentwriteUpdate the body of an existing comment on a JIRA issue in the ${jiraInstanceType}. Use jira_getIssueComments to find the comment id.
jira_uploadAttachmentwriteUpload a local file as an attachment to a JIRA issue in the ${jiraInstanceType}. The file must live under the server-configured upload directory; the path is given relative to that directory.
jira_watchIssuewriteAdd yourself (the authenticated user) as a watcher on a JIRA issue in the ${jiraInstanceType}. Only the calling user can be added; there is no way to watch on behalf of someone else.
04

Trust audit

CAUTIONgrade C · trust 79/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (15)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/common/src/__tests__/runtime-config.test.ts:21
token: 'CONFLUENCE_API_TOKEN',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/common/src/config/__tests__/sources/home-file.test.ts:22
token: 'CONFLUENCE_API_TOKEN',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/common/src/config/__tests__/sources/process-env.test.ts:19
token: 'CONFLUENCE_API_TOKEN',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
packages/confluence/src/config.ts:12
token: 'CONFLUENCE_API_TOKEN',
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
jira_unlinkIssues, jira_unwatchIssue
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/common/src/__tests__/attachment-gateway.test.ts:147
const dest = await resolveDownloadDestination({ requestedName: '../../etc/passwd', side: side() });
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/common/src/config/__tests__/sources/env-file.test.ts:4
import { EnvFileSource, ATLASSIAN_DC_MCP_CONFIG_FILE_ENV_VAR } from '../../sources/env-file.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/common/src/config/__tests__/sources/env-file.test.ts:5
import type { ProductDefinition } from '../../source.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/common/src/config/__tests__/sources/home-file.test.ts:4
import { HomeFileSource, getHomeFilePath, HOME_DIR_NAME } from '../../sources/home-file.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
packages/common/src/config/__tests__/sources/home-file.test.ts:5
import type { ProductDefinition } from '../../source.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@types/node, jest, lerna, nodemon, ts-node, typescript
Why it matters. 6 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/bitbucket/package.json
@atlassian-dc-mcp/common, @modelcontextprotocol/sdk, dotenv, zod, @modelcontextprotocol/inspector, @types/jest, lerna, nodemon
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/common/package.json
@modelcontextprotocol/sdk, @types/node, nodemon, ts-node
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/confluence/package.json
@atlassian-dc-mcp/common, @modelcontextprotocol/sdk, dotenv, zod, @modelcontextprotocol/inspector, nodemon, ts-node
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
packages/jira/package.json
@atlassian-dc-mcp/common, @modelcontextprotocol/sdk, dotenv, zod, @modelcontextprotocol/inspector, nodemon, ts-node
Why it matters. 7 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 8b5cac96ae81full audit observations/trust-audit/mcp-server/b1ff__atlassian-data-center.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-078b5cac96ae81CAUTIONC79first audit
06

Questions

What is the Atlassian Data Center MCP server?

MCP servers for the Atlassian products (Bitbucket, Confluence, JIRA) of the Data Center version

What tools does Atlassian Data Center expose?

51 in total: 33 read-only, 16 that write, and 2 that can delete or overwrite (jira_unlinkIssues, jira_unwatchIssue). Every one is listed on this page with its risk.

Is Atlassian Data Center safe to connect to an agent?

With care. The audit graded it C (79/100) and found 15 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Atlassian Data Center need?

It reads BITBUCKET_API_TOKEN, CONFLUENCE_API_TOKEN and JIRA_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Atlassian Data Center run?

It speaks sse and stdio, so it runs as a local process your client starts. It is published on npm as @atlassian-dc-mcp/jira at 0.35.0.

How current is this page?

The grade is for one exact copy of the source (8b5cac96ae81), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement