jira-user-story

Pass

Audited by Gen Agent Trust Hub on Jul 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured instructions for generating Jira ticket content based on user input and codebase context. It does not perform any sensitive file access, network operations, or privileged command execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input and codebase files to generate documentation, representing a standard indirect prompt injection surface.
  • Ingestion points: User-provided story descriptions, existing ticket text, and codebase files accessed via search/read tools in SKILL.md.
  • Boundary markers: No explicit delimiters are defined for wrapping external content.
  • Capability inventory: Tool usage is limited to codebase exploration (read/search) and text generation in chat.
  • Sanitization: No specific sanitization or escaping of input data is mentioned.
  • This surface is considered low-risk given the skill's restricted output format (Jira Markup) and its intended use as a documentation aid.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 4, 2026, 07:24 PM
Security Audit — agent-trust-hub — jira-user-story