jira-expert

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from Atlassian Jira, creating a surface for indirect prompt injection.
  • Ingestion points: The agent retrieves issue summaries, descriptions, and comments via mcp jira search_issues and related operations described in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters in the prompt to treat data retrieved from Jira as untrusted or to ignore instructions embedded within ticket content.
  • Capability inventory: The agent has significant capabilities including create_project, update_issue, create_sprint, and create_filter as defined in the Atlassian MCP Integration section of SKILL.md.
  • Sanitization: No sanitization or validation logic is present in the instructions or the provided helper scripts (jql_query_builder.py) to filter out potentially malicious natural language instructions contained within Jira data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 01:58 PM