ensure-epic-jira-issue

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a bash helper script (resolve-platform.sh) to detect the project's tracking and version control platforms. It executes standard tools like python for configuration parsing and git for remote detection.
  • [SAFE]: Metadata extraction from project files is performed using yaml.safe_load, which is a secure method for parsing YAML content and protects against remote code execution during data processing.
  • [COMMAND_EXECUTION]: The tracker_call_with_retry function in the helper script provides a robust mechanism for executing GitHub CLI commands with exponential backoff, restricted to internal tool operations.
  • [DATA_EXFILTRATION]: The skill identifies a surface for potential indirect prompt injection as it ingests untrusted data from the repository (Ingestion points: EPIC_FILE_PATH content in SKILL.md; Boundary markers: None; Capability inventory: getJiraIssue MCP tool and local file writing; Sanitization: Uses yaml.safe_load for parsing). However, the risk is mitigated by the specific extraction of structured fields.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:01 AM
Security Audit — agent-trust-hub — ensure-epic-jira-issue