jira-driven-planning
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a standard workflow for task decomposition and implementation planning without attempting to bypass safety constraints, access sensitive system files, or execute unauthorized commands.
- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it ingests data from external platforms (Jira and Confluence). However, this is considered safe because the skill's output is purely informational and lacks a mechanism for executing embedded instructions.
- Ingestion points: Jira tickets and Confluence documents in
SKILL.md. - Boundary markers: Absent; there are no specific markers used to distinguish external data from the skill's primary instructions.
- Capability inventory: The skill has no capabilities for file modification, network communication, or system command execution.
- Sanitization: No input sanitization or validation of the external content is performed.
Audit Metadata