agile
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation provides standard instructions to install the
mcp-atlassianpackage for Jira and Confluence integration. This package is from a well-known service provider. - [COMMAND_EXECUTION]: The skill suggests running the Atlassian MCP server using
uvx, a standard and secure tool for executing Python-based CLI applications. - [PROMPT_INJECTION]: The skill ingests untrusted data in the form of user stories and acceptance criteria (SKILL.md) and passes them to sub-agents via the TaskCreate capability. While this creates an indirect prompt injection surface with no explicit boundary markers or sanitization, it is the primary intended functionality of the skill.
- [SAFE]: Detailed instructions for configuring Jira API tokens recommend using local configuration files, which is consistent with standard secret management practices. No malicious code, exfiltration, or persistence mechanisms were found.
Audit Metadata