confluence — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited confluence (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Fetch content from Confluence pages and their comments via the Atlassian MCP.
Confluence lives under the same Atlassian Cloud tenant as Jira. In most setups the Jira MCP (`mcp__jira__jira_get`) can reach Confluence endpoints too — just pass a Confluence path (/wiki/rest/api/content/...).
Priority order:
WebFetch on authenticated Confluence URLs.All examples below use mcp__jira__jira_get. If you fall back to the dedicated Confluence MCP, the paths are the same; only the tool name changes.
# Search for a page by title
/confluence search "Authentication Design Doc"
# Get a page by ID
/confluence 123456
# Get a page by URL
/confluence https://myorg.atlassian.net/wiki/spaces/ENG/pages/123456Determine intent from the arguments provided.
If the user provides a search term (not a numeric ID or URL):
mcp__jira__jira_get with:
path: /wiki/rest/api/content/search
queryParams:
cql: 'title ~ "<search term>" OR text ~ "<search term>"'
limit: "10"
jq: '{results: [.results[] | {id: .id, title: .title, space: .space.key, url: ._links.webui}]}'Present results as a table and ask the user which page to fetch.
If the user provides a page ID or after selecting from search results:
mcp__jira__jira_get with:
path: /wiki/rest/api/content/<pageId>
queryParams:
expand: "body.storage,version,space,ancestors"
jq: '{id: id, title: title, space: space.key, version: version.number, ancestors: [ancestors[].title], body: body.storage.value}'If the user asks for comments on a page:
mcp__jira__jira_get with:
path: /wiki/rest/api/content/<pageId>/child/comment
queryParams:
expand: "body.storage,version"
jq: '{comments: [.results[] | {author: .version.by.displayName, date: .version.when, body: .body.storage.value}]}'If the user provides a Confluence URL, extract the page ID:
https://<domain>/wiki/spaces/<spaceKey>/pages/<pageId>/<title><pageId> with step 2.Provide:
Strip HTML/XML tags from the storage format body to present clean readable text.
Page: Authentication Design Doc
Space: ENG
Version: 12
Path: Engineering > Architecture > Auth
---
## Overview
This document describes the authentication flow for...
---
Comments (3):
- Alice (2026-01-15): Approved, looks good.
- Bob (2026-01-14): Can we add a sequence diagram?
- Carol (2026-01-13): Initial review — see inline comments.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.