confluence-expert

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from external Confluence pages, which could contain hidden instructions intended to manipulate the agent's behavior.
  • Ingestion points: Data enters the agent's context through the search and get_children tool operations defined in SKILL.md.
  • Boundary markers: The instructions lack explicit directives to wrap retrieved content in delimiters or use warnings to ignore embedded instructions.
  • Capability inventory: The skill provides the agent with extensive write permissions, including create_space, create_page, update_page, and delete_page (documented in SKILL.md).
  • Sanitization: There is no evidence of content sanitization or validation processes for data fetched from the Confluence environment.
  • [SAFE]: The Python scripts scripts/content_audit_analyzer.py and scripts/space_structure_generator.py utilize only standard libraries (json, sys, datetime, argparse) and perform local data processing without network access.
  • [SAFE]: No hardcoded credentials, API keys, or sensitive file path accesses were found across the skill's scripts or documentation.
  • [SAFE]: No obfuscation techniques, such as Base64-encoded payloads, zero-width characters, or homoglyph attacks, were detected in any of the analyzed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:32 PM