⚠️ This snapshot is over 30 days old — treat the grade as stale until the next refresh. Re-scan locally to verify.
Trust Card · Static snapshot
sooperset__mcp-atlassian C
64/100 · 2 findings (2 critical) · scope broad · Ranked #32 of 53 scanned.
Scanned 2026-09-09 · engine v0.1.0 (8 regex rules, OWASP-mapped) · upstream sooperset/mcp-atlassian @ 74bdaa8 (2026-09-05)
Score breakdown
Score constrained by 2 critical and 0 high-severity findings.
Fix first (2 critical/high)
| Severity | Rule | Finding | Remediation |
|---|---|---|---|
| CRITICAL | AT-SEC-002 (LLM02) | Hardcoded Credential or API Secrettests/unit/servers/test_confluence_server.py:216Evidence: client_secret="server_client_secret", | Move credentials to secure environment variables or a key vault. Never commit API keys. |
| CRITICAL | AT-SEC-002 (LLM02) | Hardcoded Credential or API Secrettests/unit/servers/test_jira_server.py:427Evidence: client_secret="server_client_secret", | Move credentials to secure environment variables or a key vault. Never commit API keys. |
Permissions
Scope: broad · Shell: disabled · Network egress: yes · File deletion: enabled · Human approval: none
Provenance
License: MIT · Lockfile: no · Security policy: yes · Signals: unverified origin
Independently scanned by the AgentTrust registry (not self-reported by the project). Static analysis only — no code executed, findings need human triage, counts may include test/example code. Static snapshot; re-scan before relying on it: npx @eulogik/agenttrust scan https://github.com/sooperset/mcp-atlassian. Scores move with every upstream commit; pages refresh weekly. How scoring works.