jira-expert
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from Atlassian Jira, creating a surface for indirect prompt injection.
- Ingestion points: The agent retrieves issue summaries, descriptions, and comments via
mcp jira search_issuesand related operations described inSKILL.md. - Boundary markers: There are no explicit instructions or delimiters in the prompt to treat data retrieved from Jira as untrusted or to ignore instructions embedded within ticket content.
- Capability inventory: The agent has significant capabilities including
create_project,update_issue,create_sprint, andcreate_filteras defined in theAtlassian MCP Integrationsection ofSKILL.md. - Sanitization: No sanitization or validation logic is present in the instructions or the provided helper scripts (
jql_query_builder.py) to filter out potentially malicious natural language instructions contained within Jira data.
Audit Metadata