io.github.freema/mcp-jira-stdio
NPM · MCP-JIRA-STDIO · SCANNED SEP 20
MCP server for Jira Cloud — issues, search, comments, attachments, transitions.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security89
- No malware found by supply-chain analysis.Pass
- CVE check failed: a known high-severity CVE affects marked 0.8.2, reached via md-to-adf > marked. A fixed version is available. View diagnostics → Fail
- No install/post-install scripts declared.Pass
- 36 of 111 dependencies flagged as unhealthy (1 deprecated). View diagnostics → Partial
Provenance & Transparency97
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to freema/mcp-jira-stdio). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 40 days ago).Pass
- Security-disclosure policy not yet verified: we couldn't inspect the source repository.Unverified
Schema Quality & AI Usability75
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2909 tokens (~126/item across 23 items; 23 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management90
- Stability observed for 27 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 23 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the io.github.freema/mcp-jira-stdio server?
io.github.freema/mcp-jira-stdio runs locally as an npm package, launched with npx -y mcp-jira-stdio. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · mcp-jira-stdio
claude mcp add freema-mcp-jira-stdio -- npx -y mcp-jira-stdio
{
"mcpServers": {
"freema-mcp-jira-stdio": {
"command": "npx",
"args": [
"-y",
"mcp-jira-stdio"
]
}
}
} {
"servers": {
"freema-mcp-jira-stdio": {
"command": "npx",
"args": [
"-y",
"mcp-jira-stdio"
]
}
}
} codex mcp add freema-mcp-jira-stdio -- npx -y mcp-jira-stdio
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"freema-mcp-jira-stdio": {
"type": "local",
"command": [
"npx",
"-y",
"mcp-jira-stdio"
],
"enabled": true
}
}
} openclaw mcp add freema-mcp-jira-stdio --command npx --arg -y --arg mcp-jira-stdio
mcp_servers:
freema-mcp-jira-stdio:
command: "npx"
args: ["-y", "mcp-jira-stdio"] {
"McpServers": {
"freema-mcp-jira-stdio": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"mcp-jira-stdio"
]
}
}
} assistant mcp add freema-mcp-jira-stdio -t stdio -c npx -a -y mcp-jira-stdio
{
"mcpServers": {
"freema-mcp-jira-stdio": {
"command": "npx",
"args": [
"-y",
"mcp-jira-stdio"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 0
- Security disclosure: fail → unverified ▼ functional
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 −3
- Stability: pass → 0.80 functional
- 16 Sept 26 +1
- Stability: 0.97 → pass security
- Package version: 1.11.0 → 1.11.1 functional
- 14 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 90 to 93. That category is still filling its 30-day observation window: 27 days of observed history at the previous scan, 28 at this one. The score rises as the window fills, whether or not the server changes.
- 12 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 83 to 87. That category is still filling its 30-day observation window: 25 days of observed history at the previous scan, 26 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 0
- Package version: 1.11.0 → 1.11.1 functional
- 10 Sept 26 −3
- Stability: pass → 0.80 functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Analysed npm/mcp-jira-stdio@1.11.1
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | freema/mcp-jira-stdio |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/freema/mcp-jira-stdio/.github/workflows/publish.yml@refs/tags/v1.11.1 |
| Rekor log index | 2408542714 |
| Predicate type | https://slsa.dev/provenance/v1 |
| Subject digest | sha512:9343e8c6b0b467ca5fe5f45ceeb26628873fae96efdbdae5bc96aca7cbbd3fe787861205ae60a316c2dfcf53c44be4ad4b5f2ad20d38e5ae6bc8b3e14 |
Background: How many MCP packages publish verified provenance →
Vulnerabilities 2 findings
| ID | CVE | Severity | Vector | Fix available |
|---|---|---|---|---|
| GHSA-5v2h-r2cx-5xgj | CVE-2022-21681 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
| GHSA-rrrm-qjm4-v8hf | CVE-2022-21680 | high | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | yes |
Background: What a vulnerability scan can and cannot prove →
Dependencies 111 packages
| Packages resolved | 111 |
|---|---|
| Deprecated | 1 |
| Stale | 36 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
jira_add_attachment ~290
Uploads an attachment (image, document, etc.) to a Jira issue. **EFFICIENT METHOD (recommended for large files):** - fileUrl: Provide URL to remote file - MINIMAL tokens (~60 tokens) Example: Upload to Dropbox/S3/imgur first, then provide URL **DIRECT METHOD (for small files):** - content: Base64 encoded content - WARNING: HIGH token cost (~330,000 tokens for 1MB file) Only suitable for small files (< 500 KB) Returns attachment metadata including ID and download URL. To reference the image in a comment or description, use wiki markup: !filename.png! or !filename.png|thumbnail!
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | Base64-encoded or plain text content. WARNING: HIGH token cost (~330k tokens for 1MB file). Use fileUrl for large files or upload to cloud storage first. |
| fileUrl | string | – | URL to download file from (efficient for remote files, ~60 tokens). Upload large files to Dropbox/S3/imgur first, then use URL. |
| filename | string | yes | Name of the file to attach |
| isBase64 | boolean | – | Whether content is base64-encoded (default: true). Set to false for plain text files. |
| issueKey | string | yes | Issue key to add attachment to (e.g., PROJECT-123) |
No output schema declared.
No examples provided.
jira_add_comment ~135
Adds a comment to an issue. Supports visibility restrictions for groups or roles. Comment format is controlled by the "format" parameter (default: markdown). Returns the created comment with author details and timestamp.
| Name | Type | Req | Description |
|---|---|---|---|
| body | string | yes | Comment body text |
| format | string | – | Comment format: "markdown" (converts Markdown to ADF), "adf" (use as-is ADF object), "plain" (converts plain text to ADF with basic formatting). Default: "markdown" |
| issueKey | string | yes | Issue key to add comment to |
| visibility | object | – | Comment visibility restrictions |
No output schema declared.
No examples provided.
jira_create_issue ~289
Creates a new Jira issue in the specified project. Supports setting issue type, priority, assignee, labels, components, and custom fields. Description format is controlled by the "format" parameter (default: markdown). For required custom fields, supply them via customFields (e.g., { "customfield_12345": { id: "..." } }). Returns the created issue with all details.
| Name | Type | Req | Description |
|---|---|---|---|
| assignee | string | – | Assignee account ID |
| components | array | – | Component names |
| customFields | object | – | Additional Jira field mappings, e.g. { "customfield_12345": value }. Use for required custom fields. |
| description | – | – | Issue description. Accepts plain text or ADF object. |
| format | string | – | Description format: "markdown" (converts Markdown to ADF), "adf" (use as-is ADF object), "plain" (converts plain text to ADF with basic formatting). Default: "markdown" |
| issueType | string | yes | Issue type (e.g., Bug, Story, Task) |
| labels | array | – | Issue labels |
| priority | string | – | Issue priority |
| projectKey | string | yes | Project key where the issue will be created |
| returnIssue | boolean | – | When false, skip fetching full issue after creation |
| summary | string | yes | Issue summary/title |
No output schema declared.
No examples provided.
jira_create_issue_link ~103
Creates a link between two Jira issues. Supports common link types like "blocks", "relates", "duplicates", and "clones". Use this to establish relationships between issues.
| Name | Type | Req | Description |
|---|---|---|---|
| fromIssue | string | yes | Source issue key |
| linkType | string | yes | Link type: "blocks", "is blocked by", "relates", "duplicates", "clones", or custom link type name |
| toIssue | string | yes | Target issue key |
No output schema declared.
No examples provided.
jira_create_subtask ~191
Creates a subtask under an existing parent issue. Automatically determines the correct project and subtask issue type. Supports setting priority, assignee, labels, and components. Description format is controlled by the "format" parameter (default: markdown).
| Name | Type | Req | Description |
|---|---|---|---|
| assignee | string | – | Assignee account ID |
| components | array | – | Component names |
| description | – | – | Subtask description. Accepts plain text or ADF object. |
| format | string | – | Description format: "markdown" (converts Markdown to ADF), "adf" (use as-is ADF object), "plain" (converts plain text to ADF with basic formatting). Default: "markdown" |
| labels | array | – | Subtask labels |
| parentIssueKey | string | yes | Parent issue key |
| priority | string | – | Subtask priority |
| summary | string | yes | Subtask summary/title |
No output schema declared.
No examples provided.
jira_delete_attachment ~43
Deletes an attachment from Jira by its attachment ID. Use jira_get_attachments to find attachment IDs.
| Name | Type | Req | Description |
|---|---|---|---|
| attachmentId | string | yes | ID of the attachment to delete |
No output schema declared.
No examples provided.
jira_get_attachments ~56
Lists all attachments on a Jira issue. Returns attachment metadata including filename, size, MIME type, author, and download URL.
| Name | Type | Req | Description |
|---|---|---|---|
| issueKey | string | yes | Issue key to get attachments for (e.g., PROJECT-123) |
No output schema declared.
No examples provided.
jira_get_comments ~122
Retrieves all comments for a Jira issue. Returns comment author, content, timestamps, and visibility settings. Supports pagination for issues with many comments.
| Name | Type | Req | Description |
|---|---|---|---|
| issueKey | string | yes | Issue key to get comments for (e.g., PROJECT-123) |
| maxResults | number | – | Maximum number of comments to return (default: 50) |
| orderBy | string | – | Sort order for comments: "created" (oldest first), "-created" (newest first) |
| startAt | number | – | Index of first comment to return (for pagination) |
No output schema declared.
No examples provided.
jira_get_create_meta ~89
Retrieves create metadata for a project, showing all available fields (including custom fields) for creating issues. Shows required vs optional fields, field types, and allowed values. Use this before creating issues to discover what fields are needed.
| Name | Type | Req | Description |
|---|---|---|---|
| issueTypeName | string | – | Specific issue type name to get metadata for (optional) |
| projectKey | string | yes | Project key to get create metadata for |
No output schema declared.
No examples provided.
jira_get_custom_fields ~64
Retrieves all custom fields available in Jira. Shows custom field names, IDs (e.g., customfield_10071), and types. Useful for discovering what custom fields exist and their identifiers.
| Name | Type | Req | Description |
|---|---|---|---|
| projectKey | string | – | Project key to filter custom fields (optional) |
No output schema declared.
No examples provided.
jira_get_issue ~142
Retrieve details for a specific Jira issue by key or URL. Use this when the user mentions an issue like "PAYWALL-943" or pastes a Jira link (e.g., https://your.atlassian.net/browse/PAYWALL-943). Returns status, assignee, priority, project, type, labels, components, timestamps, and description.
| Name | Type | Req | Description |
|---|---|---|---|
| expand | array | – | Additional issue details to include |
| fields | array | – | Specific fields to retrieve |
| issueKey | string | yes | Issue key or full Jira URL (e.g., PROJECT-123 or https://your.atlassian.net/browse/PROJECT-123) |
No output schema declared.
No examples provided.
jira_get_issue_graph ~228
Build a dependency/relationship graph starting from a seed issue. Returns a map of connected issues (parent/child hierarchy, blocks, relates to, duplicates, etc.) with nodes and edges, plus a Mermaid diagram for visualization. Use this to understand how issues are connected across epics, stories, and subtasks.
| Name | Type | Req | Description |
|---|---|---|---|
| direction | string | – | Which link directions to follow: "all", "inward", or "outward" (default: "all") |
| includeHierarchy | boolean | – | Include parent/child/subtask edges (default: true) |
| issueKey | string | yes | Seed issue key to start graph traversal from (e.g., PROJECT-123) |
| linkTypes | array | – | Filter to specific link types (e.g., ["Blocks", "Relates"]). If omitted, includes all link types. |
| maxDepth | number | – | Maximum BFS traversal depth from seed issue (default: 2, max: 5) |
| maxNodes | number | – | Maximum number of nodes to include in the graph (default: 50, max: 200) |
No output schema declared.
No examples provided.
jira_get_issue_types ~59
Retrieves available issue types. Can get global issue types or project-specific issue types including regular issues and subtasks (Bug, Story, Task, Epic, etc.).
| Name | Type | Req | Description |
|---|---|---|---|
| projectKey | string | – | Project key to get issue types for specific project |
No output schema declared.
No examples provided.
jira_get_my_issues ~107
Retrieves issues assigned to current user, sorted by most recently updated first. Supports pagination and field selection. For pagination, use nextPageToken from previous response.
| Name | Type | Req | Description |
|---|---|---|---|
| expand | array | – | Additional details to include |
| fields | array | – | Specific fields to retrieve |
| maxResults | number | – | Maximum number of results to return per page |
| nextPageToken | string | – | Token for pagination. Omit for first page, use value from previous response for next page. |
No output schema declared.
No examples provided.
jira_get_priorities ~35
Retrieves available priorities (e.g., Highest, High, Medium, Low, Lowest). Returns IDs, names, and descriptions.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
jira_get_project_info ~63
Retrieves detailed information about a project (components, versions, issue types, roles, insights). More comprehensive than the basic project list.
| Name | Type | Req | Description |
|---|---|---|---|
| expand | array | – | Additional project details to include |
| projectKey | string | yes | Project key to get detailed information for |
No output schema declared.
No examples provided.
jira_get_statuses ~72
Retrieves available statuses (global or project-specific, e.g., To Do, In Progress, Done). Returns status categories and workflow information.
| Name | Type | Req | Description |
|---|---|---|---|
| issueTypeId | string | – | Issue type ID to get statuses for specific issue type |
| projectKey | string | – | Project key to get statuses for specific project |
No output schema declared.
No examples provided.
jira_get_transitions ~60
Retrieves all available workflow transitions for a Jira issue. Use this to discover which status changes are possible for an issue before calling jira_transition_issue.
| Name | Type | Req | Description |
|---|---|---|---|
| issueKey | string | yes | Issue key to get available transitions for (e.g., PROJECT-123) |
No output schema declared.
No examples provided.
jira_get_users ~107
Search for users by name, email, username, or account ID. Returns display name, email, account status, and account type. Supports pagination.
| Name | Type | Req | Description |
|---|---|---|---|
| accountId | string | – | Specific account ID to search for |
| maxResults | number | – | Maximum number of results to return |
| query | string | – | Search query for user name or email |
| startAt | number | – | Index of first result to return |
| username | string | – | Specific username to search for |
No output schema declared.
No examples provided.
jira_get_visible_projects ~55
Retrieves all projects accessible to the authenticated user. Returns project keys, names, descriptions, and basic metadata.
| Name | Type | Req | Description |
|---|---|---|---|
| expand | array | – | Additional project details to include |
| recent | number | – | Limit to recently accessed projects |
No output schema declared.
No examples provided.
jira_search_issues ~134
Search for Jira issues using JQL. Supports complex queries with pagination and field selection. Examples: "project = PROJECT AND status = Open", "assignee = currentUser()". For pagination, use nextPageToken from previous response.
| Name | Type | Req | Description |
|---|---|---|---|
| expand | array | – | Additional details to include |
| fields | array | – | Specific fields to retrieve |
| jql | string | yes | JQL query string |
| maxResults | number | – | Maximum number of results to return per page |
| nextPageToken | string | – | Token for pagination. Omit for first page, use value from previous response for next page. |
No output schema declared.
No examples provided.
jira_transition_issue ~228
Transitions a Jira issue to a new workflow status (e.g., "To Do" -> "In Progress" -> "Done"). Use jira_get_transitions first to discover available transitions. Supports adding a comment and setting resolution during the transition.
| Name | Type | Req | Description |
|---|---|---|---|
| comment | string | – | Optional comment to add when transitioning the issue |
| format | string | – | Comment format: "markdown" (converts Markdown to ADF), "adf" (use as-is ADF object), "plain" (converts plain text to ADF with basic formatting). Default: "markdown" |
| issueKey | string | yes | Issue key to transition (e.g., PROJECT-123) |
| resolution | string | – | Resolution name when transitioning to a resolved/done status (e.g., "Done", "Fixed") |
| transitionId | string | – | ID of the transition to perform. Use jira_get_transitions to find available transition IDs. |
| transitionName | string | – | Name of the transition to perform (e.g., "In Progress", "Done"). Case-insensitive. Alternative to transitionId. |
No output schema declared.
No examples provided.
jira_update_issue ~237
Updates an existing Jira issue by its key. Supports updating summary, description, priority, assignee, labels, and components. Description format is controlled by the "format" parameter (default: markdown). Only specified fields will be updated.
| Name | Type | Req | Description |
|---|---|---|---|
| assignee | string | – | New assignee account ID |
| components | array | – | New components (replaces existing) |
| description | – | – | New description. Accepts plain text or ADF object. |
| format | string | – | Description format: "markdown" (converts Markdown to ADF), "adf" (use as-is ADF object), "plain" (converts plain text to ADF with basic formatting). Default: "markdown" |
| issueKey | string | yes | Issue key to update |
| labels | array | – | New labels (replaces existing) |
| parent | string | – | New parent issue key (e.g., PROJECT-100). Set to empty string to remove the parent. |
| priority | string | – | New priority |
| returnIssue | boolean | – | When false, skip fetching full issue after update |
| summary | string | – | New summary |
No output schema declared.
No examples provided.
What is the io.github.freema/mcp-jira-stdio server?
io.github.freema/mcp-jira-stdio is listed in the public MCP registry as io.github.freema/mcp-jira-stdio. MCP server for Jira Cloud, issues, search, comments, attachments, transitions. This page covers its npm package (mcp-jira-stdio).
Is the io.github.freema/mcp-jira-stdio server safe to use?
io.github.freema/mcp-jira-stdio scores 90 out of 100 on VerifyMCP. We recorded 2 known advisories against it as of 20 September 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the io.github.freema/mcp-jira-stdio server expose?
io.github.freema/mcp-jira-stdio exposes 23 tools: jira_get_visible_projects, jira_get_issue, jira_search_issues, jira_get_my_issues, jira_get_issue_types, and 18 more. Their descriptions and schemas cost roughly 2,909 tokens of context every time the server is loaded.
Is the io.github.freema/mcp-jira-stdio server still maintained?
io.github.freema/mcp-jira-stdio is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the io.github.freema/mcp-jira-stdio server under?
io.github.freema/mcp-jira-stdio declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.