jira-issue-to-pr
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches untrusted descriptions from Jira tickets and interpolates them directly into the prompt for a spawned autonomous agent conversation without any sanitization or strict boundary markers.
- Ingestion points: The
scripts/main.pyscript retrieves thedescriptionfield from Jira issues via the Atlassian REST API. - Boundary markers: The Jira content is placed into a prompt template with minimal context ("Description: {description}") and no explicit instructions for the LLM to ignore potentially malicious instructions embedded in the ticket body.
- Capability inventory: The agent spawned by this skill is configured with a
NeverConfirmpolicy and a local workspace, giving it the capability to autonomously clone repositories, implement code changes, and push to GitHub. - Sanitization: There is no evidence of filtering, escaping, or validation of the Jira ticket content before it is processed by the downstream agent.
Audit Metadata