Execute Jira and Confluence operations with endpoint discovery, payload construction, and authentication.
77
97%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The skill resolves and issues HTTP API requests to arbitrary Atlassian URLs (extracted from the required `url`/`instructions`) via scripts/request.py and auto-fetches and processes Jira/Confluence API responses (user-generated issues/pages/comments) which the agent reads and uses (e.g., pagination and subsequent actions), exposing it to untrusted third-party content from those public or user-generated Atlassian sources.