Back to skill

Security audit

Jira

Security checks for vulnerabilities and agentic risk

Overview

This Jira skill is coherent, but needs Review because crafted issue text can make its shell wrapper run local code and it can change live Jira data without built-in confirmation.

Install only if you are comfortable granting this skill Jira API access. Use a dedicated low-privilege Jira account/token, avoid feeding untrusted issue text into create/comment/update commands until the Python argument handling is fixed, and require explicit confirmation for any command that changes Jira issues.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
jira-cli.sh:125
Finding

Arbitrary Python Code Execution Through Unsafe CLI Argument Interpolation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
jira-cli.sh:17
Finding

Jira API Credentials Passed in Curl Process Arguments

Content
View full analysis
&2 exit 1 fi echo "$body" } ``` ```bash jira_post() { local response http_code body response=$(curl -s -w "\n%{http_code}" -u "$AUTH" \ -X POST -H "Content-Type: application/json" -H "Accept: application/json" \ "$1" -d "$2") http_code=$(echo "$response" | tail -1) body=$(echo "$response" | sed '$d') if [ "$http_code" -ge 400 ]; then echo "{\"error\": \"HTTP $http_code\", \"url\": \"$1\", \"response\": $body}" >&2 exit 1 fi echo "$body" } ``` ```bash jira_put() { local response http_code body response=$(curl -s -w "\n%{http_code}" -u "$AUTH" \ -X PUT -H "Content-Type: application/json" -H "Accept: application/json" \ "$1" -d "$2") http_code=$(echo "$response" | tail -1) body=$(echo "$response" | sed '$d') if [ "$http_code" -ge 400 ]; then echo "{\"error\": \"HTTP $http_code\", \"url\": \"$1\", \"response\": $body}" >&2 exit 1 fi if [ -n "$body" ]; then echo "$body"; else echo '{"success":true}'; fi } ``` ### Technical Analysis Command-line arguments may be observable through operating-system process inspection, process accounting, audit systems, endpoint telemetry, debugging tools, or command execut ...[truncated 1896 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill exposes sensitive capabilities (environment variables containing Jira credentials, shell execution via a CLI wrapper, and network access to Jira Cloud) but does not declare an explicit tool scope such as allowed tools or permissions. This increases the risk of overbroad execution and misuse because an agent or platform cannot reliably constrain what the skill is allowed to access or invoke.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This skill can create, update, assign, comment on, and transition Jira issues, but the usage guidance does not clearly warn that these actions modify live Jira data. In agent-driven environments, omission of mutation warnings can lead to accidental unauthorized or unintended changes, especially when users ask exploratory questions and the agent treats destructive operations as routine.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · jira-cli.sh (reported line 37)May include surrounding context.

sh
jira_post() {
    local response http_code body
    response=$(curl -s -w "\n%{http_code}" -u "$AUTH" \
        -X POST -H "Content-Type: application/json" -H "Accept: application/json" \
        "$1" -d "$2")
    http_code=$(echo "$response" | tail -1)

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · jira-cli.sh (reported line 51)May include surrounding context.

sh
jira_put() {
    local response http_code body
    response=$(curl -s -w "\n%{http_code}" -u "$AUTH" \
        -X PUT -H "Content-Type: application/json" -H "Accept: application/json" \
        "$1" -d "$2")
    http_code=$(echo "$response" | tail -1)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says the skill manages Jira issues via search/create/update/comment/transition, but the script also exposes user enumeration, project listing, and assignee modification. This expands the available privilege surface beyond the declared scope, enabling organizational reconnaissance and identity lookup that a caller may not expect from the stated capability set.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This shell script requires and reads ATLASSIAN_API_TOKEN and ATLASSIAN_EMAIL to authenticate to Jira, but it provides no warning in comments, help output, or other user-facing text that sensitive credentials will be used for API access. For code files, access to sensitive environment variables should have some disclosure unless clearly warned elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.