jira-issue-to-pr

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches untrusted descriptions from Jira tickets and interpolates them directly into the prompt for a spawned autonomous agent conversation without any sanitization or strict boundary markers.
  • Ingestion points: The scripts/main.py script retrieves the description field from Jira issues via the Atlassian REST API.
  • Boundary markers: The Jira content is placed into a prompt template with minimal context ("Description: {description}") and no explicit instructions for the LLM to ignore potentially malicious instructions embedded in the ticket body.
  • Capability inventory: The agent spawned by this skill is configured with a NeverConfirm policy and a local workspace, giving it the capability to autonomously clone repositories, implement code changes, and push to GitHub.
  • Sanitization: There is no evidence of filtering, escaping, or validation of the Jira ticket content before it is processed by the downstream agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:07 PM
Security Audit — agent-trust-hub — jira-issue-to-pr