jira-integration

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves ticket information from Jira, which could contain instructions designed to manipulate the agent's behavior.
  • Ingestion points: Ticket summaries, descriptions, and comments are fetched via tools like jira_get_issue and REST API calls defined in SKILL.md.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to isolate external Jira data from the agent's core instructions.
  • Capability inventory: The agent can execute network requests via curl and perform modifications like updating issues and adding comments.
  • Sanitization: No sanitization logic is provided to filter or escape potentially malicious input within Jira fields.
  • [EXTERNAL_DOWNLOADS]: The instructions suggest installing the mcp-atlassian package using uvx to provide the Jira integration capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — jira-integration