044-planning-jira

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill incorporates explicit defensive instructions to treat all external Jira content as untrusted and specifically directs the agent to ignore any embedded instructions or policy claims within that data.- [CREDENTIALS_UNSAFE]: The workflow emphasizes secure secret management, directing users to use OS-native credential stores via the Jira CLI and explicitly forbidding the display or transmission of API tokens in the agent's output.- [COMMAND_EXECUTION]: The skill guides the user through the installation of the jira-cli tool using standard package managers (Homebrew, Chocolatey) or manual binary placement, requiring explicit user interaction and verification.- [DATA_EXFILTRATION]: By enforcing a 'sanitized inventory' policy and prohibiting the ingestion of raw Jira command output, the skill prevents sensitive project information from entering the agent context without human review.- [SAFE]: The skill demonstrates best practices for handling external tool integration by implementing an interactive gate for installation and requiring human-in-the-loop verification before processing external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 11:00 AM
Security Audit — agent-trust-hub — 044-planning-jira