jira-ticket
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface by ingesting content from external Jira issues, Confluence pages, and Datadog logs to drive implementation decisions.
- Ingestion points: Jira summary, description, and comments via Atlassian MCP; Confluence pages; and Datadog traces/logs/spans.
- Boundary markers: No specific delimiters or instructions to ignore embedded directions in fetched data are defined.
- Capability inventory: The skill possesses the capability to modify repository files, create branches, and execute autonomous implementation via the $dev toolset.
- Sanitization: No explicit sanitization or validation of external ticket content is described in the workflow.
- [EXTERNAL_DOWNLOADS]: The skill is configured to interact with external Atlassian (Jira/Confluence) and Datadog environments using Model Context Protocol (MCP) tools. This is a primary function of the skill to gather necessary context for software development tasks.
Audit Metadata