Back to skill

Security audit

Jira 事务工具包基础版

Security checks for vulnerabilities and agentic risk

Overview

This Jira skill is not clearly malicious, but it can run commands and change Jira data while its trigger and privacy guidance are too broad and partly misleading.

Review before installing. Use this only with a least-privilege Jira account, expect Jira issue data and credentials to be used with Atlassian/Jira backends, and require explicit confirmation before any create, update, transition, assignment, or comment action. Do not rely on the artifact's broad local-only privacy statement.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The skill claims that FREE-version data is stored locally and not uploaded to the cloud, but elsewhere it explicitly requires network access to external APIs and Jira backends. This creates a misleading security assurance that may cause users to expose Jira content, comments, metadata, or credentials under false assumptions about data handling.

Description-Behavior Mismatch

Medium
Confidence
82% confidence
Finding
The trigger conditions say to use the skill for data analysis, reporting, statistical insights, and visualization, which does not match the Jira transaction-management capabilities described elsewhere. This mismatch can cause the agent to invoke the skill in unrelated contexts, increasing the chance of unnecessary command execution or unintended Jira operations.

Vague Triggers

High
Confidence
91% confidence
Finding
The trigger condition is overly broad and mismatched to the actual Jira scope, so an agent may select this skill for generic analysis or visualization requests. In an MD+EXEC skill that can run commands and modify Jira data, over-selection materially raises the risk of unintended side effects or data exposure.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The natural-language invocation guidance tells the agent to execute operations from broad user descriptions without specifying validation, confirmation, or boundaries. In a skill with exec access and write-capable Jira actions, ambiguous invocation can lead to accidental issue changes or command execution from loosely phrased requests.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises natural-language Jira interaction but does not prominently warn that it can execute shell commands and perform state-changing Jira operations. Users and higher-level agents may treat it like a passive helper, increasing the likelihood of invoking destructive or privacy-impacting actions without informed consent.

Static analysis

No suspicious patterns detected.