jira

Pass

Audited by Gen Agent Trust Hub on May 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the @membranehq/cli package from the NPM registry to provide its core functionality. This is a vendor-provided tool for interacting with the Membrane platform.- [COMMAND_EXECUTION]: The skill uses the membrane command-line interface to perform Jira operations, manage authentication flows, and execute custom API requests through a proxy.- [PROMPT_INJECTION]: As the skill reads issue descriptions and comments from Jira, it is subject to indirect prompt injection risks (Category 8) where malicious content in a ticket could attempt to influence the agent's behavior. Evidence includes ingestion points in get-issue and get-comments actions, combined with write capabilities like update-issue and delete-issue. No specific boundary markers or sanitization steps are defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 10, 2026, 07:53 PM