MCP Clients: Understanding the potential security risks

A note to Atlassian customers

The use of MCP clients with Atlassian products is a customer-elected action. In May 2025, Atlassian released our own Remote MCP Server to provide our customers with a trusted server to experiment with this leading-edge technology. Learn more here: https://atlassian.reaktivdev.com/announcements/remote-mcp-server.

As the industry experiments with this technology, new risks are emerging. We are carefully assessing the potential risks, and are sharing some practical precautions that organizations should consider before deploying AI agents that utilize MCP with their Atlassian data.

While these measures are not exhaustive, they may help reduce security risks.

What is MCP?

Key Definitions

Model Context Protocol (MCP) is an open standard that offers a universal method to connect large language models (LLMs) with various data sources and tools. This user-friendly technology promises quicker development cycles, scalability, and interoperable workflows, thereby standardizing AI-tool integrations.

Organizations, including Atlassian customers, are increasingly experimenting with MCP clients to enable AI agents to interact with tools and data more effectively. However, despite the convenience they offer, permitting AI agents to operate on behalf of humans through MCP carries inherent risks that should be considered.

Potential security risks associated with use of MCP Clients


As this technology is relatively new, the security implications are still being investigated. Some risks identified include:

Security considerations


We recommend that before customers use AI agents leveraging MCP with their Atlassian data, they assess relevant risks and implement appropriate security measures. Some measures you may consider include:

We believe AI and emerging technologies are important to the forward progress of all kinds of teams. We also strongly encourage our customers to carefully assess any risks specific to their use cases.

Exit mobile version