jira-driven-planning

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows a standard workflow for task decomposition and implementation planning without attempting to bypass safety constraints, access sensitive system files, or execute unauthorized commands.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it ingests data from external platforms (Jira and Confluence). However, this is considered safe because the skill's output is purely informational and lacks a mechanism for executing embedded instructions.
  • Ingestion points: Jira tickets and Confluence documents in SKILL.md.
  • Boundary markers: Absent; there are no specific markers used to distinguish external data from the skill's primary instructions.
  • Capability inventory: The skill has no capabilities for file modification, network communication, or system command execution.
  • Sanitization: No input sanitization or validation of the external content is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 11:59 PM
Security Audit — agent-trust-hub — jira-driven-planning