confluence-expert
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to read and analyze documentation from external Confluence spaces, creating a potential vector for indirect prompt injection attacks where malicious content in a page could influence agent behavior.
- Ingestion points:
SKILL.mdexplicitly lists "Extract documentation for analysis" as a key operation under the Atlassian MCP Integration section. - Boundary markers: There are no instructions or delimiters defined to separate the extracted documentation from the agent's core instructions.
- Capability inventory: The skill has significant capabilities including space management, page creation/deletion, and permission configuration via the Confluence MCP Server (specified in
SKILL.md). - Sanitization: The skill lacks any mentioned mechanisms to sanitize or validate the content retrieved from Confluence before processing.
Audit Metadata