THRONE
See report Verify server

registry / record

github.com/sooperset/mcp-atlassian

github / sealed 2026-06-16 / No. 472064ed

Does github.com/sooperset/mcp-atlassian MCP work in Claude Code and Cursor? Throne executed github.com/sooperset/mcp-atlassian mcp in a single-use Firecracker microVM and replayed both recorded client behaviours. Compatibility verdict: fit. Is github.com/sooperset/mcp-atlassian mcp safe? Static security scan: 8 finding(s) to review under security ruleset v1. The full per-step results, security findings, scan date, and evidence hash are below.

> throne registry github.com/sooperset/mcp-atlassian sealed
receiptsealed evidence
scan id
472064ed007246bdb7184aee2ce221e2
target
https://github.com/sooperset/mcp-atlassian
sealed at
2026-06-16 17:04:07Z
evidence hash
sha256:01aa339ed91cbb7e0b8e946620211bcf44398c0e42a5ed079cfab4c8c35733f8
01connectPASS5.0s

initialize ok: server Atlassian MCP 2.14.5, negotiated protocolVersion 2025-11-25, capabilities ['experimental', 'prompts', 'resources', 'tasks', 'tools']

02discoverPASS9ms

supported: tools/list (0 tools), resources/list (0), prompts/list (0)

03validate_schemasNOT_APPLICABLE0ms

no tools declared; nothing to validate

04smoke_test_toolsNOT_APPLICABLE0ms

no tools declared; nothing to smoke test

05error_handlingPASS8.5s

structured error responses, connection survived, wrong_type_args: skipped (no tools declared); unknown_method: error(-32602); invalid_id: no response (silent), connection alive; oversized_input: accepted (returned result); recovery: accepted (returned result); cancellation: accepted (returned result); old_version: accepted old version 2024-10-07, negotiated 2025-11-25, server may have stale protocol handling

06streamingNOT_APPLICABLE1ms

no streaming-capable tool declared by this server

07resource_lifecycleNOT_APPLICABLE28ms

server declares resources but lists none

08concurrent_callsNOT_APPLICABLE0ms

no tools declared; nothing to call concurrently

09reconnectPASS2.6s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

01connectPASS3.7s

initialize ok: server Atlassian MCP 2.14.5, negotiated protocolVersion 2025-11-25, capabilities ['experimental', 'prompts', 'resources', 'tasks', 'tools'] [request_strategy=pipelined, connection_count=2, second connection established]

02discoverPASS64ms

supported: tools/list (0 tools), resources/list (0), prompts/list (0); notes: connection 2 confirms 0 tools

03validate_schemasNOT_APPLICABLE0ms

no tools declared; nothing to validate

04smoke_test_toolsNOT_APPLICABLE0ms

no tools declared; nothing to smoke test

05error_handlingPASS8.0s

structured error responses, connection survived, wrong_type_args: skipped (no tools declared); unknown_method: error(-32602); invalid_id: no response (silent), connection alive; oversized_input: accepted (returned result); recovery: accepted (returned result); cancellation: accepted (returned result); old_version: accepted old version 2024-10-07, negotiated 2025-11-25, server may have stale protocol handling

06streamingNOT_APPLICABLE0ms

no streaming-capable tool declared by this server

07resource_lifecycleNOT_APPLICABLE11ms

server declares resources but lists none

08concurrent_callsNOT_APPLICABLE0ms

no tools declared; nothing to call concurrently

09reconnectPASS4.5s

transport closed and relaunched; re-handshake ok (protocolVersion 2025-11-25, first session was 2025-11-25)

chatgpt desktop calibratingemulation profile pending real-traffic captureCOMING SOON
SECURITY: REVIEW / 8 finding(s) (7 medium) / review recommended
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value test… (26 chars), verify it is not a live credential

mcp-atlassian-HEAD/tests/unit/auth/test_authentication.py:208
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value test… (26 chars), verify it is not a live credential

mcp-atlassian-HEAD/tests/unit/auth/test_authentication.py:237
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value test… (19 chars), verify it is not a live credential

mcp-atlassian-HEAD/tests/unit/confluence/test_client.py:85
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value test… (19 chars), verify it is not a live credential

mcp-atlassian-HEAD/tests/unit/jira/test_client.py:86
MEDIUMTHR-SECRET-02 / Hardcoded secrets or tokens in source

token assigned a literal value unex… (16 chars), verify it is not a live credential

mcp-atlassian-HEAD/tests/unit/servers/test_dependencies.py:676
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

subprocess.run() called with a dynamically built command (heuristic, review): ''

mcp-atlassian-HEAD/tests/unit/test_stdin_monitoring_fix.py:42
MEDIUMTHR-EXEC-04 / Arbitrary command execution from tool arguments

subprocess.run() called with a dynamically built command (heuristic, review): ''

mcp-atlassian-HEAD/tests/unit/test_stdio_lifecycle.py:34
LOWTHR-NET-05 / Hardcoded outbound endpoints

13 non-local endpoint host(s) referenced in code, verify each is expected for this server's purpose: api.atlassian.com (mcp-atlassian-HEAD/src/mcp_atlassian/confluence/client.py:65), auth.atlassian.com (mcp-atlassian-HEAD/src/mcp_atlassian/utils/oauth.py:29), chat.openai.com (mcp-atlassian-HEAD/src/mcp_atlassian/servers/main.py:59), chatgpt.com (mcp-atlassian-HEAD/src/mcp_atlassian/servers/main.py:58), cli.github.com (mcp-atlassian-HEAD/.devcontainer/post-create.sh:15), developer.atlassian.com (mcp-atlassian-HEAD/src/mcp_atlassian/confluence/constants.py:3), dl.yarnpkg.com (mcp-atlassian-HEAD/.devcontainer/post-create.sh:26), example.atlassian.net (mcp-atlassian-HEAD/src/mcp_atlassian/servers/confluence.py:138), jira.atlassian.com (mcp-atlassian-HEAD/src/mcp_atlassian/preprocessing/jira.py:29), jira.your-company.com (mcp-atlassian-HEAD/src/mcp_atlassian/__init__.py:180), support.atlassian.com (mcp-atlassian-HEAD/src/mcp_atlassian/jira/constants.py:3), your-company.atlassian.net (mcp-atlassian-HEAD/src/mcp_atlassian/confluence/config.py:97), your-domain.atlassian.net (mcp-atlassian-HEAD/src/mcp_atlassian/__init__.py:161)

mcp-atlassian-HEAD/.devcontainer/post-create.sh:15
VERDICT: FIT8 of 18 steps exercised across 2 clientsSANDBOXED RUN, submitted server executed in a disposable microVM, compatibility: 0 fail / 0 warn (8 of 18 steps exercised across 2 clients) / security: review, 8 finding(s), 0 highsealed by THRONE / No. 472064ed / 2026-06-16
scopeattestation tuple
target
https://github.com/sooperset/mcp-atlassian github
engine
sandboxed
claude code
calibration: partial recorded=9,spec=0,assumed=9
cursor
calibration: partial recorded=11,spec=0,assumed=7
chatgpt desktop
calibration: unavailable recorded=0,spec=2,assumed=16
steps exercised
8 of 18
test suite
v1.0.0
security ruleset
v1.0.0
sealed at
2026-06-16 17:04:07Z
evidence hash
sha256:01aa339ed91cbb7e0b8e946620211bcf44398c0e42a5ed079cfab4c8c35733f8
valid until
2026-09-14
THRONE: FITwear the crown

paste this in your README. it renders the live verdict and links back to this record. if a release ever breaks the verdict, the badge says so on its own.

[![THRONE: FIT](https://api.usethrone.dev/api/badge/https%3A%2F%2Fgithub.com%2Fsooperset%2Fmcp-atlassian)](https://usethrone.dev/server/sooperset-mcp-atlassian)
executed in a disposable microVM, created for this scan and destroyed after it. nothing outlives a run.

maintainer of this server? challenge this record: hello@usethrone.dev. tell us what we got wrong and we re-run it in the open.

this page renders the stored record of a real run. nothing on it is asserted without the execution that proved it.