Back to skill

Security audit

Jira API工具

Security checks across malware telemetry and agentic risk

Overview

This Jira skill is not overtly malicious, but it asks for broad command/file powers and can change or delete Jira data without clearly scoped safeguards.

Review this skill carefully before installing. Use it only with least-privilege Jira/Maton credentials, avoid granting delete or broad project-admin scopes unless needed, and require explicit confirmation before closing, deleting, bulk-changing, or writing Jira data. Treat any local command execution or file-writing request as separate from normal Jira API use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill claims it can execute system commands in a sandbox even though the rest of the document presents it as a Jira API integration. This mismatch can cause an agent or user to invoke high-risk execution capabilities under the assumption they are only interacting with a SaaS API, expanding the attack surface and enabling unintended command execution workflows.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The description says to use the skill broadly for API integration, interface docking, webhook configuration, and system connection scenarios, which is far wider than a narrowly defined Jira task scope. Overbroad invocation criteria can cause agents to select this skill in inappropriate contexts, exposing credentials or enabling powerful tools like read/write/exec where they are not needed.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The FAQ states that the tool supports closing and deleting issues but does not clearly warn about irreversible or workflow-impacting consequences. In a skill that can automate Jira operations, this increases the chance an agent or user will perform destructive actions on production issue data without informed confirmation.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.