lisa-jira-sync

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes untrusted data from JIRA ticket fields and comments. 1. Ingestion points: Ticket metadata and comments are fetched via the lisa-atlassian-access tool, and plan files are read from the local plans directory. 2. Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or isolate embedded commands within the external data. 3. Capability inventory: The skill has access to Bash execution and can perform JIRA operations like commenting and transitioning statuses. 4. Sanitization: The skill does not specify any sanitization or validation logic for the content retrieved from external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 06:31 AM
Security Audit — agent-trust-hub — lisa-jira-sync