Back to skill

Security audit

Jira 事务工具包基础版

Security checks across malware telemetry and agentic risk

Overview

This Jira skill is mostly purpose-aligned, but it can change remote Jira data while also making an overbroad trigger claim and an inaccurate local-only privacy claim.

Review this before installing if your Jira projects contain sensitive business data. Use it only with a Jira account whose permissions are appropriate, confirm any create/update/transition/comment action before it runs, and do not rely on the local-only privacy claim when using Jira CLI or Atlassian MCP backends.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document claims that FREE version data is stored locally and not uploaded to the cloud, but elsewhere it explicitly supports Jira CLI and MCP/server backends that necessarily send issue content, comments, and metadata to external Jira/Atlassian services. This is a security-relevant misrepresentation because users may disclose sensitive project data under a false assumption of local-only processing.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger conditions mention broad data-analysis and reporting scenarios that do not match the Jira-focused capabilities described elsewhere. Overbroad activation criteria can cause an agent to invoke this skill outside intended scope, increasing the chance of unnecessary command execution or remote Jira actions on unrelated prompts.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill describes examples that execute CLI commands and use external Jira/MCP services, but it does not clearly warn users that these actions may modify remote project data or transmit sensitive issue content to third-party systems. In an agent context, lack of prominent execution and network warnings raises the risk of users authorizing dangerous actions without informed consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.