Atlassian IntegrationCAUTION
MCP server connecting AI assistants with Jira & Confluence for smart project management.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](https://github.com/phuc-nt/mcp-atlassian-server) [](https://smithery.ai/server/@phuc-nt/mcp-atlassian-server)
What's New in Version 2.1.1 🚀
- Refactored the entire codebase to standardize resource/tool structure, completely removed the content-metadata resource, and merged metadata into the page resource.
- New developer guide: anyone can now easily extend and maintain the codebase.
- Ensured compatibility with the latest MCP SDK, improved security, scalability, and maintainability.
- Updated
docs/introduction/resources-and-tools.mdto remove all references to content-metadata.
👉 See the full CHANGELOG for details.
What's New in Version 2.0.1 🎉
MCP Atlassian Server v2.0.1 brings a major expansion of features and capabilities!
- Updated APIs: Now using the latest Atlassian APIs (Jira API v3, Confluence API v2)
- Expanded Features: Grown from 21 to 48 features, including advanced Jira and Confluence capabilities
- Enhanced Board & Sprint Management: Complete Agile/Scrum workflow support
- Advanced Confluence Features: Page version management, attachments handling, and comment management
- Improved Resource Registration: Fixed duplicate resource registration issues for a more stable experience
- Documentation Update: New comprehensive documentation series explaining MCP architecture, resource/tool development
For full details on all changes, improvements, and fixes, see the CHANGELOG.
Introduction
MCP Atlassian Server (by phuc-nt) is a Model Context Protocol (MCP) server that connects AI agents like Cline, Claude Desktop, or Cursor to Atlassian Jira and Con
49c48eb019beOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-atlassian-server --env ATLASSIAN_API_TOKEN=${ATLASSIAN_API_TOKEN} -- npx -y @phuc-nt/[email protected]{
"mcpServers": {
"mcp-atlassian-server": {
"command": "npx",
"args": [
"-y",
"@phuc-nt/[email protected]"
],
"env": {
"ATLASSIAN_API_TOKEN": "${ATLASSIAN_API_TOKEN}"
}
}
}
}Exposed tools (24)
4 read · 16 write · 4 destructive. Blast radius: 4 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
addComment | write | Add a comment to a Confluence page |
addGadgetToDashboard | write | Add gadget to Jira dashboard (POST /rest/api/3/dashboard/{dashboardId}/gadget) |
addIssueToSprint | write | Add issues to a Jira sprint (POST /rest/agile/1.0/sprint/{sprintId}/issue) |
addIssuesToBacklog | write | Move issue(s) to Jira backlog (POST /rest/agile/1.0/backlog/issue or /rest/agile/1.0/backlog/{boardId}/issue) |
assignIssue | read | Assign a Jira issue to a user |
closeSprint | read | Close a Jira sprint |
createDashboard | write | Create a new Jira dashboard |
createFilter | write | Create a new filter in Jira |
createIssue | write | Create a new issue in Jira |
createPage | write | Create a new page in Confluence (API v2, chỉ hỗ trợ spaceId) |
createSprint | write | Create a new sprint in Jira |
deleteFilter | destructive | Delete a filter in Jira |
deleteFooterComment | destructive | Delete a footer comment in Confluence (API v2) |
deletePage | destructive | Delete a Confluence page (API v2) |
rankBacklogIssues | read | Rank issues in Jira backlog |
removeGadgetFromDashboard | destructive | Remove gadget from Jira dashboard |
startSprint | write | Start a Jira sprint |
transitionIssue | read | Transition the status of a Jira issue |
updateDashboard | write | Update a Jira dashboard |
updateFilter | write | Update an existing filter in Jira |
updateFooterComment | write | Update a footer comment in Confluence (API v2) |
updateIssue | write | Update information of a Jira issue |
updatePage | write | Update the content and information of a Confluence page |
updatePageTitle | write | Update the title of a Confluence page (API v2) |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (6 observation(s))
- Network
- declared (5 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
logger.debug(`Token length: ${config.apiToken?.length || 0} characters`);deleteFilter, deleteFooterComment, deletePage, removeGadgetFromDashboard
import { Logger } from '../../utils/logger.js';import { Logger } from '../../utils/logger.js';import { pagesListSchema, pageSchema, commentsListSchema, attachmentListSchema, versionListSchema, labelListSchema } from '../../schemas/confluence.js';import { getConfluencePagesV2, getConfluencePageV2, getConfluencePageBodyV2, getConfluencePageAncestorsV2, getConfluencePageChildrenV2, getConfluencePageLabelsV2, getConfluencePageAttachmentsV2, getCoimport { getConfluencePageFooterCommentsV2, getConfluencePageInlineCommentsV2 } from '../../utils/confluence-resource-api.js';@modelcontextprotocol/sdk, @types/node, ts-node, typescript
@modelcontextprotocol/sdk, axios, axios-retry, cross-fetch, dotenv, jira.js, zod, @types/jest
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash
Gates applied: no_behavioural_pass.
49c48eb019befull audit observations/trust-audit/mcp-server/phuc-nt__atlassian-integration-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 49c48eb019be | CAUTION | B | 89 | first audit |
Questions
What is the Atlassian Integration MCP server?
MCP server connecting AI assistants with Jira & Confluence for smart project management.
What tools does Atlassian Integration expose?
24 in total: 4 read-only, 16 that write, and 4 that can delete or overwrite (deleteFilter, deleteFooterComment, deletePage, removeGadgetFromDashboard). Every one is listed on this page with its risk.
Is Atlassian Integration safe to connect to an agent?
With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 4 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Atlassian Integration need?
It reads ATLASSIAN_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Atlassian Integration run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as @phuc-nt/mcp-atlassian-server at 2.1.1.
How current is this page?
The grade is for one exact copy of the source (49c48eb019be), read on 2026-10-08. The repository is watched and re-audited when it changes.