Atlas / MCP servers / phuc-nt / Atlassian Integration

Atlassian IntegrationCAUTION

mcp/phuc-nt/atlassian-integration-1

MCP server connecting AI assistants with Jira & Confluence for smart project management.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
24 4r · 16w · 4d
Transport
stdio
License
MIT
Stars
52
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://github.com/phuc-nt/mcp-atlassian-server) [](https://smithery.ai/server/@phuc-nt/mcp-atlassian-server)

What's New in Version 2.1.1 🚀

  • Refactored the entire codebase to standardize resource/tool structure, completely removed the content-metadata resource, and merged metadata into the page resource.
  • New developer guide: anyone can now easily extend and maintain the codebase.
  • Ensured compatibility with the latest MCP SDK, improved security, scalability, and maintainability.
  • Updated docs/introduction/resources-and-tools.md to remove all references to content-metadata.

👉 See the full CHANGELOG for details.

What's New in Version 2.0.1 🎉

MCP Atlassian Server v2.0.1 brings a major expansion of features and capabilities!

  • Updated APIs: Now using the latest Atlassian APIs (Jira API v3, Confluence API v2)
  • Expanded Features: Grown from 21 to 48 features, including advanced Jira and Confluence capabilities
  • Enhanced Board & Sprint Management: Complete Agile/Scrum workflow support
  • Advanced Confluence Features: Page version management, attachments handling, and comment management
  • Improved Resource Registration: Fixed duplicate resource registration issues for a more stable experience
  • Documentation Update: New comprehensive documentation series explaining MCP architecture, resource/tool development

For full details on all changes, improvements, and fixes, see the CHANGELOG.

Introduction

MCP Atlassian Server (by phuc-nt) is a Model Context Protocol (MCP) server that connects AI agents like Cline, Claude Desktop, or Cursor to Atlassian Jira and Con

Read from source at commit 49c48eb019beOBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-atlassian-server --env ATLASSIAN_API_TOKEN=${ATLASSIAN_API_TOKEN} -- npx -y @phuc-nt/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-atlassian-server": {
      "command": "npx",
      "args": [
        "-y",
        "@phuc-nt/[email protected]"
      ],
      "env": {
        "ATLASSIAN_API_TOKEN": "${ATLASSIAN_API_TOKEN}"
      }
    }
  }
}
03

Exposed tools (24)

4 read · 16 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
addCommentwriteAdd a comment to a Confluence page
addGadgetToDashboardwriteAdd gadget to Jira dashboard (POST /rest/api/3/dashboard/{dashboardId}/gadget)
addIssueToSprintwriteAdd issues to a Jira sprint (POST /rest/agile/1.0/sprint/{sprintId}/issue)
addIssuesToBacklogwriteMove issue(s) to Jira backlog (POST /rest/agile/1.0/backlog/issue or /rest/agile/1.0/backlog/{boardId}/issue)
assignIssuereadAssign a Jira issue to a user
closeSprintreadClose a Jira sprint
createDashboardwriteCreate a new Jira dashboard
createFilterwriteCreate a new filter in Jira
createIssuewriteCreate a new issue in Jira
createPagewriteCreate a new page in Confluence (API v2, chỉ hỗ trợ spaceId)
createSprintwriteCreate a new sprint in Jira
deleteFilterdestructiveDelete a filter in Jira
deleteFooterCommentdestructiveDelete a footer comment in Confluence (API v2)
deletePagedestructiveDelete a Confluence page (API v2)
rankBacklogIssuesreadRank issues in Jira backlog
removeGadgetFromDashboarddestructiveRemove gadget from Jira dashboard
startSprintwriteStart a Jira sprint
transitionIssuereadTransition the status of a Jira issue
updateDashboardwriteUpdate a Jira dashboard
updateFilterwriteUpdate an existing filter in Jira
updateFooterCommentwriteUpdate a footer comment in Confluence (API v2)
updateIssuewriteUpdate information of a Jira issue
updatePagewriteUpdate the content and information of a Confluence page
updatePageTitlewriteUpdate the title of a Confluence page (API v2)
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (6 observation(s))
Network
declared (5 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/utils/atlassian-api-base.ts:168
logger.debug(`Token length: ${config.apiToken?.length || 0} characters`);
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
deleteFilter, deleteFooterComment, deletePage, removeGadgetFromDashboard
Why it matters. 4 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/confluence/index.ts:4
import { Logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/confluence/pages.ts:2
import { Logger } from '../../utils/logger.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/confluence/pages.ts:3
import { pagesListSchema, pageSchema, commentsListSchema, attachmentListSchema, versionListSchema, labelListSchema } from '../../schemas/confluence.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/confluence/pages.ts:4
import { getConfluencePagesV2, getConfluencePageV2, getConfluencePageBodyV2, getConfluencePageAncestorsV2, getConfluencePageChildrenV2, getConfluencePageLabelsV2, getConfluencePageAttachmentsV2, getCo
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/resources/confluence/pages.ts:5
import { getConfluencePageFooterCommentsV2, getConfluencePageInlineCommentsV2 } from '../../utils/confluence-resource-api.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
dev_mcp-atlassian-test-client/package.json
@modelcontextprotocol/sdk, @types/node, ts-node, typescript
Why it matters. 4 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, axios, axios-retry, cross-fetch, dotenv, jira.js, zod, @types/jest
Why it matters. 14 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
llms-install.md:101
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 49c48eb019befull audit observations/trust-audit/mcp-server/phuc-nt__atlassian-integration-1.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-0849c48eb019beCAUTIONB89first audit
06

Questions

What is the Atlassian Integration MCP server?

MCP server connecting AI assistants with Jira & Confluence for smart project management.

What tools does Atlassian Integration expose?

24 in total: 4 read-only, 16 that write, and 4 that can delete or overwrite (deleteFilter, deleteFooterComment, deletePage, removeGadgetFromDashboard). Every one is listed on this page with its risk.

Is Atlassian Integration safe to connect to an agent?

With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Atlassian Integration need?

It reads ATLASSIAN_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Atlassian Integration run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @phuc-nt/mcp-atlassian-server at 2.1.1.

How current is this page?

The grade is for one exact copy of the source (49c48eb019be), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement