backlog-manager

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill performs legitimate conversion of markdown specifications into JIRA epics, stories, and subtasks using Atlassian MCP tools.
  • [SAFE]: Security is significantly bolstered by Step 3, which requires explicit user approval of the proposed ticket hierarchy and execution engine assignments before any external state changes occur.
  • [SAFE]: No evidence of hardcoded credentials, unauthorized network access, or persistence mechanisms was found; the use of the 'ontoledgy.atlassian.net' domain is consistent with the skill's authorship.
  • [PROMPT_INJECTION]: The skill processes untrusted documentation files (tasks.md, requirements.md, design.md) into the agent context. (1) Ingestion points: Phase 2 workflow reading from the local repo. (2) Boundary markers: Absent. (3) Capability inventory: createJiraIssue, editJiraIssue, addCommentToJiraIssue via Atlassian MCP. (4) Sanitization: Absent. The indirect prompt injection surface is documented as safe due to the human-in-the-loop validation step and the specialized nature of the ticket-creation tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 07:50 AM
Security Audit — agent-trust-hub — backlog-manager