jira-expert
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides guidelines and static scripts for Jira management. No command injection, unauthorized network operations, or credential harvesting patterns were detected.
- [SAFE]: All external references and integration points (GitHub, Slack, PagerDuty, Confluence) are documented as standard operational components for the intended use case.
- [INDIRECT_PROMPT_INJECTION]: The skill includes scripts that ingest external Jira data in JSON format. While this creates a data ingestion surface, the scripts (
board_optimizer.py,issue_quality_checker.py,workflow_analyzer.py) perform only statistical analysis and logic checks on the input without dynamic code execution (e.g., eval/exec). - Ingestion points: The scripts process external issue and board configuration data via CLI arguments.
- Boundary markers: None explicitly defined in scripts, but they utilize standard JSON parsing which isolates data from logic.
- Capability inventory: The skill allows the agent to execute JQL queries and perform Jira configuration changes via an MCP server.
- Sanitization: The Python scripts use typed parsing and regular expression matching for validation, which effectively sanitizes input for the script's own execution context.
Audit Metadata