filing-jira-tickets
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements safety-first execution patterns for interacting with external APIs. It defaults to a 'dry run' mode for ticket creation and linking, requiring the agent to preview the exact payload before execution.
- [SAFE]: Mandatory human-in-the-loop validation is enforced. The instructions explicitly state that nothing should be created without user approval unless the user has specifically opted out, which is a key defense against autonomous errors or unintended actions.
- [SAFE]: The skill uses specific MCP tools (
mcp__plugin_bitwarden-atlassian-tools_bitwarden-atlassian__get_create_fields) that are consistent with the author's identity (Bitwarden) and the skill's stated purpose of managing Atlassian Jira projects. - [SAFE]: The drafting instructions provide a form of data sanitization by directing the agent to 'translate the work into fields' and explicitly warning 'Do not paste in whatever the source document said.' This reduces the likelihood of indirect prompt injection attacks where malicious instructions in a source document might be blindly copied into a Jira ticket.
Audit Metadata