Atlassian Ai Toolkit — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Atlassian Ai Toolkit (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
AI-first SDK, CLI, and MCP server for Atlassian Jira and Confluence
A Bun monorepo containing a typed SDK, an agent-native CLI, and an MCP server for Atlassian Cloud APIs.
| Package | Description |
|---|---|
@atlassian-ai-toolkit/sdk | Core SDK with types, API client, and business logic |
@atlassian-ai-toolkit/cli | Command-line interface (Stricli) |
@atlassian-ai-toolkit/mcp | MCP server for AI assistants (FastMCP) |
No Node.js, no npm, no PATH conflicts. One file built with Bun.
macOS and Linux:
curl -fsSL https://raw.githubusercontent.com/spenserhale/atlassian-ai-toolkit/main/scripts/install.sh | shThe script detects your OS + architecture, downloads the matching binary from the latest release, verifies its SHA256, and installs to $HOME/.local/bin/atlassian.
Pin a version with ATLASSIAN_AI_TOOLKIT_VERSION=v0.1.0 or change the install directory with ATLASSIAN_AI_TOOLKIT_INSTALL=$HOME/bin.
Windows: download atlassian-windows-x64.exe from the latest release and put it on your PATH.
Available binaries: atlassian-linux-{x64,arm64}, atlassian-darwin-{x64,arm64}, and atlassian-windows-x64.exe.
Set Atlassian Cloud credentials in your shell:
export ATLASSIAN_SITE_URL="https://your-site.atlassian.net"
export ATLASSIAN_EMAIL="[email protected]"
export ATLASSIAN_API_TOKEN="your-api-token"Create a scoped API token at <https://id.atlassian.com/manage-profile/security/api-tokens>.
Deletes preview by default. Actual deletion requires --force and a matching --confirm value from the fetched resource.
# Preview the permanent Jira delete
atlassian jira delete PROJ-123
# Permanently delete the Jira issue
atlassian jira delete PROJ-123 --force --confirm PROJ-123
# Preview moving a Confluence page to trash
atlassian confluence delete 123456
# Move a Confluence page to trash
atlassian confluence delete 123456 --force --confirm 123456
# Permanently purge an already-trashed Confluence page
atlassian confluence delete 123456 --purge --force --confirm 123456# Install dependencies
bun install
# Build all packages
bun run build
# Run the CLI
bun run dev:cli -- --help
# Run the MCP server (stdio mode for Claude Desktop)
bun run dev:mcpThe token should be scoped to the smallest set of Jira and Confluence permissions needed for the workflow. Third-party reference implementations live under refs/, which is intentionally gitignored so this repo never vendors or executes unreviewed code with local credentials.
packages/sdk/ <-- Types, API client, business logic (foundation)
^ ^
| |
packages/cli/ packages/mcp/
(Stricli) (FastMCP)Both the CLI and MCP server are thin wrappers over the SDK. If the REST API changes, you update the SDK and both consumers get the fix automatically.
# Run tests across all packages
bun test
# Build a specific package
cd packages/sdk && bun run buildpackages/sdk/src/types.tspackages/sdk/src/client.tspackages/cli/src/commands/packages/mcp/src/tools/Destructive operations must default to a preview path and require an explicit --force flag in the CLI or force: true in MCP tools.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.