scriptrunner-documentation

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [SAFE]: The skill consists exclusively of markdown documentation and related image assets. It does not contain any executable scripts, shell commands, or instructions that could compromise the AI agent's environment or behavior.
  • [EXTERNAL_DOWNLOADS]: The documentation includes numerous links to official ScriptRunner and Atlassian resources. All identified external URLs point to legitimate, well-known technical documentation sites and vendor-owned domains (adaptavist.com, atlassian.com, scriptrunnerhq.com) which are standard for product support content.
  • [SAFE]: Automated security scans flagged a URL (http://board.id) as a phishing risk and the containing documentation file (references/docs/cloud/features/script-listeners/bindings-and-parameters.md) as malicious. Manual inspection confirms that this is an accidental hyperlink generated by a markdown processor from a code property example (board.id). In the context of API documentation, this is a clear false positive and does not represent a security threat.
  • [NO_CODE]: The skill does not bundle any executable code or configuration files that initiate network or file system operations; its primary function is providing localized content for the agent to reference.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 02:06 PM
Security Audit — agent-trust-hub — scriptrunner-documentation