atlassian-templates

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill documentation and reference files (e.g., confluence-templates.md, jira-templates.md) contain standard, legitimate project management templates. No prompt injection or malicious instructions were detected.\n- [SAFE]: The Python utilities in the scripts/ directory are benign automation tools using standard library modules (argparse, json, sys, datetime). They do not include any dangerous functions like eval() or perform network-based exfiltration.\n- [INDIRECT_PROMPT_INJECTION]: The Python scripts process external JSON files, creating a surface for indirect prompt injection if the ingested data contains instructions targeting the agent. However, the capabilities are low-risk and the behavior is typical for data-processing tools.\n
  • Ingestion points: scripts/template_scaffolder.py, scripts/template_usage_analyzer.py, and scripts/template_validator.py read JSON files from user-specified paths.\n
  • Boundary markers: None present; the scripts interpolate JSON values directly into templates or reports without delimiters.\n
  • Capability inventory: The scripts perform local file reading and print results to stdout. They do not invoke subprocesses, write to files, or make network calls.\n
  • Sanitization: The scripts use json.load() for safe parsing, but no further sanitization is applied to the string content within the JSON fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:44 PM
Security Audit — agent-trust-hub — atlassian-templates