confluence-expert

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill includes functionality to read and analyze documentation from external Confluence spaces, creating a potential vector for indirect prompt injection attacks where malicious content in a page could influence agent behavior.
  • Ingestion points: SKILL.md explicitly lists "Extract documentation for analysis" as a key operation under the Atlassian MCP Integration section.
  • Boundary markers: There are no instructions or delimiters defined to separate the extracted documentation from the agent's core instructions.
  • Capability inventory: The skill has significant capabilities including space management, page creation/deletion, and permission configuration via the Confluence MCP Server (specified in SKILL.md).
  • Sanitization: The skill lacks any mentioned mechanisms to sanitize or validate the content retrieved from Confluence before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 12:32 PM
Security Audit — agent-trust-hub — confluence-expert