jira-operations

Pass

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection.
  • Ingestion points: The jira-as ops discover-project command ingests untrusted project metadata and workflows from external JIRA instances.
  • Boundary markers: There are no instructions or delimiters defined to separate this external data from the system prompt.
  • Capability inventory: The skill is allowed to use Bash, Read, Glob, and Grep, which provides a broad execution environment for instructions processed by the agent.
  • Sanitization: No sanitization or validation of the ingested JIRA metadata is specified before it is utilized by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 19, 2026, 02:33 AM