Back to skill

Security audit

Jira集成技能

Security checks for vulnerabilities and agentic risk

Overview

This Jira integration skill is not proven malicious, but it asks for broad local file and command-execution powers that are not tightly scoped to Jira work.

Review before installing. Use only in an environment where local file access and command execution are sandboxed or disabled, and require explicit confirmation before creating, updating, deleting, transitioning, or synchronizing Jira data. Do not expose broad Jira credentials or unrelated local secrets to this skill.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:14
Finding

Excessive System Tool Permissions for a Jira Integration Skill

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:14-17
Vulnerability Type: Excessive tool permissions and violation of least privilege
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec
- write

Technical Analysis

The skill requests general-purpose file-reading, file-writing, and command-execution capabilities even though its documented purpose is to interact with Jira through an external API. These system-level capabilities are not demonstrably necessary for issue creation, status synchronization, or Jira workflow operations.

The document later claims that commands run in a sandbox and recommends command allowlisting, but it does not define enforceable command restrictions, filesystem path boundaries, executable allowlists, or user-confirmation requirements. No implementation is included that would allow these claimed safeguards to be verified.

Granting exec, read, and write together creates a broad capability set:

  • read may expose configuration files, credentials, source code, or other local data.
  • write may modify project files, configuration, or agent-accessible state.
  • exec may invoke local programs with the privileges of the hosting agent.
  • Combining the tools can permit data discovery, modification, and command execution outside the legitimate Jira-integration scope.

This is a least-privilege failure rather than evidence of an embedded malicious payload. The reviewed file contains no specific malicious command, but its permission declaration unnecessarily expands the impact of malicious, ambiguous, or prompt-injected input.

Attack Path

  1. The Agent loads the skill and grants the declared read, write, and exec tools.
  2. An attacker supplies a crafted instruction through a user request, Jira-derived content, or other untrusted context processed by the Agent.
  3. The crafted instruction induces the Agent to interpret unrelated local file acc ...[truncated 1506 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec, read, and write from the skill unless each capability is strictly required and supported by an implemented use case.
  2. Replace general-purpose system tools with a dedicated Jira API interface exposing only required operations, such as:
    • Creating an issue.
    • Reading an explicitly identified issue.
    • Applying an allowed transition.
    • Updating an allowlisted set of fields.
  3. Restrict network access to explicitly configured Jira HTTPS origins and reject user-supplied hosts, schemes, or redirect targets.
  4. Enforce project, tenant, issue, transition, and field allowlists at the tool boundary rather than relying on natural-language instructions.
  5. If file access is genuinely required, confine it to a dedicated workspace directory, reject path traversal and symbolic-link escapes, and separate read-only from writable locations.
  6. If command execution is unavoidable, expose fixed operations instead of a shell. Do not concatenate user-controlled values into commands; use structured argument arrays and an executable allowlist.
  7. Require explicit user confirmation before issue creation, status transitions, destructive updates, or any local side effect.
  8. Apply output redaction and prevent API keys, environment variables, authorization headers, and sensitive Jira fields from entering logs or model-visible responses.
  9. Add an auditable implementation and automated security tests demonstrating that sandbox, authorization, path, command, and destination restrictions are enforced.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation description is overly broad for an API-related skill, making it more likely the agent will invoke it in situations where Jira access or side-effecting API calls are not actually intended. Overbroad routing raises the risk of accidental data modification, credential use, or unnecessary exposure of external systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

System command execution is a powerful capability that is not justified by the stated Jira integration purpose. In an agent environment, unnecessary exec access can enable arbitrary shell actions, local reconnaissance, data exfiltration, or destructive modifications if triggered by crafted prompts or weak guardrails.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quoted trigger phrase is ambiguous and underspecified, which can cause accidental activation of the skill on weak textual matches rather than clear user intent. While not directly an exploit primitive, ambiguity is dangerous here because the skill can reach external systems and potentially perform modifications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description does not clearly warn users that the skill may create, modify, or synchronize Jira data. In a skill capable of CRUD operations and workflow automation, missing write-action disclosure increases the chance of unintended state changes in production Jira environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description explicitly states '支持中文交互' as a default behavior, which imposes a language choice without offering user selection or opt-in. This can violate language or locale policy when the skill is used in multilingual environments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation claims command execution is limited to a whitelist, but no actual whitelist, enforcement mechanism, or implementation details are provided. This kind of unsupported safety claim can create false trust while the skill still broadly advertises command execution, making misuse more likely in practice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a Jira/API integration wrapper, but its documented feature set also includes local file handling and system command execution. This expands the operational scope far beyond the declared purpose, increasing the risk that the skill could access local data or execute host actions unrelated to Jira workflows, especially if an agent auto-enables listed tools.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Local file read/write access is not clearly necessary for basic Jira API integration, yet the skill advertises file processing capabilities. Unnecessary filesystem access increases the chance of reading secrets, modifying unrelated project files, or persisting sensitive Jira data locally without clear user awareness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.