Back to skill

Security audit

Jira 事务工具包专业版

Security checks across malware telemetry and agentic risk

Overview

This Jira skill is mostly aligned with Jira administration, but it asks for broad command/file access and promotes bulk Jira changes without enough built-in safeguards.

Install only if you are comfortable giving an agent Jira CLI/API access and local command execution. Before using it, require previews and explicit confirmation for creates, edits, transitions, and all bulk actions; restrict credentials to the minimum Jira permissions needed; avoid team-shared or rotating keys unless your organization has clear controls; and do not let it read or write arbitrary local files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The skill claims command execution is limited to a whitelist, but elsewhere instructs shell commands such as environment inspection and network diagnostics. This mismatch weakens operator trust and can lead an agent to execute broader commands than users expect, increasing the chance of sensitive data exposure or unsafe host interaction.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The skill is presented as a Jira administration tool, but its documented core functions expand into generic file handling. Unrelated file capabilities broaden the operational scope and create opportunities for unintended local file access or modification beyond the user's reasonable expectations.

Context-Inappropriate Capability

Low
Confidence
79% confidence
Finding
Generic file read/write functionality is not justified by the stated Jira-management purpose, violating least privilege. Even if not overtly malicious, unnecessary filesystem access increases the attack surface and the risk of accidental disclosure or tampering with local data.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation model allows broad natural-language triggering without clear task boundaries, which can cause the agent to over-apply the skill in contexts the user did not intend. In a tool that can query, create, and bulk-modify Jira data, ambiguous activation materially raises the risk of unauthorized or accidental actions.

Vague Triggers

Medium
Confidence
86% confidence
Finding
Describing the skill as appropriate whenever 'efficiency' or 'automation' is needed is overly broad and can cause the agent to invoke it outside the narrow Jira use case. Overbroad routing is especially risky here because the skill advertises external system writes, automation, and command execution.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The examples show creating Jira issues through agent-executed commands but do not prominently warn that this sends data to and mutates an external system. Users may assume the interaction is advisory or local, leading to unintended creation of tickets containing sensitive or incorrect information.

Missing User Warnings

High
Confidence
94% confidence
Finding
The skill heavily promotes bulk operations, concurrency, and workflow automation without strong up-front safeguards for irreversible or large-scale changes. In Jira, bulk edits and automated transitions can rapidly alter many records, causing widespread operational disruption, data integrity issues, and audit burdens if triggered incorrectly.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.