twg-operational-health

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates legitimate operational workflows within Atlassian products such as Jira, JSM, and Assets. It follows best practices by instructing the agent to resolve scopes and sites before execution and explicitly mentions required permissions for specific tool operations.
  • [COMMAND_EXECUTION]: The skill provides structured instructions for the agent to interact with the environment via the twg CLI tool. All commands are limited to operational data retrieval and specific schema management within the user's tenant.
  • [PROMPT_INJECTION]: The skill processes untrusted data from incident records and transcripts, which presents a surface for indirect prompt injection. However, the instructions provide logical processing boundaries by requiring the agent to cluster evidence and rank confidence before synthesis.
  • [PROMPT_INJECTION]: The skill retrieves data from Jira and JSM workitems and Assets queries. While it lacks explicit boundary markers like XML tags for ingested content, it enforces a strict evidence policy and hierarchy, which serves as a mitigation against following instructions embedded in the data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 07:04 AM
Security Audit — agent-trust-hub — twg-operational-health