jira-issue-to-pr

Fail

Audited by Snyk on Aug 14, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The automation deliberately spawns agent conversations that inherit user secrets and are configured to run without confirmation, instructing the agent to clone and modify GitHub repos referenced in Jira issues — a design that enables remote code execution and credential misuse if Jira issue content or project access is untrusted.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Jira-authored issue content flows at runtime via fetch_labeled_issues() → extract_adf_text(issue["fields"].get("description")) and is inserted into the LLM prompt before POST {agent_url}/api/conversations.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The runtime agent endpoints are fetched from the agent server (e.g. f"{agent_url}/api/settings" and f"{agent_url}/api/conversations" in scripts/main.py), and the script includes the fetched "agent_settings" in the conversation payload (which can change agent behavior and cause loading of user/public skills), so the AGENT_SERVER_URL endpoints are a runtime dependency that directly control agent behavior.

Issues (3)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 14, 2026, 12:08 PM
Issues
3
Security Audit — snyk — jira-issue-to-pr