Back to skill

Security audit

Jira PAT管理器

Security checks across malware telemetry and agentic risk

Overview

This skill claims to manage Jira access tokens but mixes that sensitive purpose with broad API, analytics, file, and command-execution language that could route it too widely.

Review carefully before installing. Only use this skill in an environment where Jira token creation, revocation, and permission changes are intended, and require explicit confirmation before any revoke or privilege-changing action. Avoid granting shell, broad file, or generic API access unless the publisher narrows and documents those capabilities.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest presents the skill as a generic API wrapper for analytics, reporting, and visualization, while the body describes privileged Jira PAT lifecycle operations. This mismatch can cause the agent to invoke the skill in unrelated contexts and expose token-creation or revocation capabilities under misleading framing, increasing the chance of unauthorized or unintended sensitive actions.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The core-functionality section claims analytics, reporting, and visualization features that conflict with a security-sensitive token-management tool. In an agent environment, such contradictory capability claims broaden routing and user expectations, making accidental invocation of privileged PAT operations more likely.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
Advertising command execution for a skill whose main purpose is Jira PAT/API management unnecessarily expands the attack surface. If an agent routes tasks here based on broad descriptions, users may be exposed to shell execution paths unrelated to PAT management, which can lead to misuse, data exposure, or arbitrary local actions.

Vague Triggers

High
Confidence
95% confidence
Finding
The activation guidance is overly broad, covering general external API use and data-analysis tasks rather than narrowly scoped Jira PAT administration. In agent ecosystems, vague routing conditions can trigger this skill for unrelated requests, granting access to sensitive token-management operations outside the user's likely intent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill uses vague and inconsistent trigger phrases, including truncated or unclear references, which undermines predictable activation behavior. Ambiguous triggers are especially risky for a privileged token-management skill because they can cause accidental selection and execution of sensitive operations.

Missing User Warnings

High
Confidence
96% confidence
Finding
The documentation describes PAT creation, revocation, and permission changes without clearly warning that these are destructive or access-affecting actions. For a credential-management skill, missing warnings can lead users or agents to revoke valid tokens, over-grant permissions, or disrupt account and automation access without informed confirmation.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.