jira-expert
Pass
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a legitimate knowledge base for Jira administration. All provided examples for JQL, workflows, and automation represent standard industry practices and use valid Jira syntax. No code execution, obfuscation, or credential harvesting patterns were found.
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it is designed to process and act upon data from Jira issues (such as summaries, descriptions, and comments) that may be authored by untrusted users. This is an inherent property of Jira management tools and is not exploited here.
- Ingestion points: Issue fields and JQL query results in SKILL.md and references/jql-examples.md.
- Boundary markers: None identified in the instructional text.
- Capability inventory: The agent can create/configure projects, execute queries, and update issue statuses via the Jira MCP server as specified in SKILL.md.
- Sanitization: No specific sanitization logic is prescribed for the input data.
Audit Metadata