T09 · Insecure Skill Coding Practices
- Location
jira-cli.sh:125- Finding
Arbitrary Python Code Execution Through Unsafe CLI Argument Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Jira skill is coherent, but needs Review because crafted issue text can make its shell wrapper run local code and it can change live Jira data without built-in confirmation.
Install only if you are comfortable granting this skill Jira API access. Use a dedicated low-privilege Jira account/token, avoid feeding untrusted issue text into create/comment/update commands until the Python argument handling is fixed, and require explicit confirmation for any command that changes Jira issues.
jira-cli.sh:125Arbitrary Python Code Execution Through Unsafe CLI Argument Interpolation
jira-cli.sh:17Jira API Credentials Passed in Curl Process Arguments
The skill exposes sensitive capabilities (environment variables containing Jira credentials, shell execution via a CLI wrapper, and network access to Jira Cloud) but does not declare an explicit tool scope such as allowed tools or permissions. This increases the risk of overbroad execution and misuse because an agent or platform cannot reliably constrain what the skill is allowed to access or invoke.
This skill can create, update, assign, comment on, and transition Jira issues, but the usage guidance does not clearly warn that these actions modify live Jira data. In agent-driven environments, omission of mutation warnings can lead to accidental unauthorized or unintended changes, especially when users ask exploratory questions and the agent treats destructive operations as routine.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
jira_post() {
local response http_code body
response=$(curl -s -w "\n%{http_code}" -u "$AUTH" \
-X POST -H "Content-Type: application/json" -H "Accept: application/json" \
"$1" -d "$2")
http_code=$(echo "$response" | tail -1)
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
jira_put() {
local response http_code body
response=$(curl -s -w "\n%{http_code}" -u "$AUTH" \
-X PUT -H "Content-Type: application/json" -H "Accept: application/json" \
"$1" -d "$2")
http_code=$(echo "$response" | tail -1)
The manifest says the skill manages Jira issues via search/create/update/comment/transition, but the script also exposes user enumeration, project listing, and assignee modification. This expands the available privilege surface beyond the declared scope, enabling organizational reconnaissance and identity lookup that a caller may not expect from the stated capability set.
This shell script requires and reads ATLASSIAN_API_TOKEN and ATLASSIAN_EMAIL to authenticate to Jira, but it provides no warning in comments, help output, or other user-facing text that sensitive credentials will be used for API access. For code files, access to sensitive environment variables should have some disclosure unless clearly warned elsewhere.
No suspicious patterns detected.