Claude security directory

Atlassian Rovo

Published by Atlassian

Medium risk

Atlassian’s Rovo MCP Server enables secure, permission-aware access to Jira and Confluence from external AI tools like Claude. It supports summarization, creation, and multi-step actions, helping teams tap into structured enterprise knowledge wherever they work-all while preserving data privacy and leveraging Atlassian’s open, interoperable Teamwork Graph foundation.

Security assessment

Plutonium assessed this web connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.

Available capabilities

This add-on exposes 31 tools or capabilities.

  • atlassianUserInfo
  • getAccessibleAtlassianResources
  • getConfluenceSpaces
  • getConfluencePage
  • getPagesInConfluenceSpace
  • getConfluencePageAncestors
  • getConfluencePageFooterComments
  • getConfluencePageInlineComments
  • getConfluencePageDescendants
  • createConfluencePage
  • updateConfluencePage
  • createConfluenceFooterComment
  • createConfluenceInlineComment
  • searchConfluenceUsingCql
  • getJiraIssue
  • editJiraIssue
  • createJiraIssue
  • getTransitionsForJiraIssue
  • transitionJiraIssue
  • lookupJiraAccountId
  • searchJiraIssuesUsingJql
  • addCommentToJiraIssue
  • getJiraIssueRemoteIssueLinks
  • getVisibleJiraProjects

The interactive security report will load automatically.