acli
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources (Jira work items and Confluence pages) which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: Commands such as
acli jira workitem view,acli jira workitem search,acli confluence page view, andacli confluence blog viewfetch content (summaries, descriptions, comments, page bodies) from Atlassian Cloud. - Boundary markers: The skill does not explicitly instruct the agent to use delimiters or specific boundary markers when processing retrieved content to distinguish it from system instructions.
- Capability inventory: The skill allows execution of shell commands via the Bash tool and file system access (Read, Grep, Glob), which could be misused if an indirect injection is successful.
- Sanitization: There are no explicit instructions for the agent to sanitize or validate the content retrieved from Jira or Confluence before acting upon it.
Audit Metadata