jira-integration
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill retrieves ticket information from Jira, which could contain instructions designed to manipulate the agent's behavior.
- Ingestion points: Ticket summaries, descriptions, and comments are fetched via tools like
jira_get_issueand REST API calls defined inSKILL.md. - Boundary markers: The skill lacks explicit boundary markers or instructions to isolate external Jira data from the agent's core instructions.
- Capability inventory: The agent can execute network requests via
curland perform modifications like updating issues and adding comments. - Sanitization: No sanitization logic is provided to filter or escape potentially malicious input within Jira fields.
- [EXTERNAL_DOWNLOADS]: The instructions suggest installing the
mcp-atlassianpackage usinguvxto provide the Jira integration capabilities.
Audit Metadata