markdown-to-confluence — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited markdown-to-confluence (Agent Skill) and scored it 96/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 1 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
The text {match} tells the agent to skip the normal "ask the user first" gate. Used adversarially it removes the human-in-the-loop check before destructive or sensitive actions, turning a normally-gated agent into a fire-and-forget executor.
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill takes one local Markdown file and publishes it to a Confluence location that the user must specify — creating a new page or updating an existing one through the Atlassian MCP server. It owns everything about the posting itself: the MCP preflight, resolving the destination, reading the file, the create-or-update call, and reporting the result. It does not write the Markdown; the caller supplies an existing file.
Callers that supply an explicit publish mode and location (for example han-atlassian:project-documentation-to-confluence) run this skill straight through without re-asking. Invoked on its own with pieces missing, it asks for them and defaults to a safe unpublished draft.
This skill cannot run without a configured and connected Atlassian MCP server.
Confirm the server is reachable by calling mcp__claude_ai_Atlassian__getAccessibleAtlassianResources to retrieve the cloud ID(s). If the tool is not available, the call errors, or it returns no accessible resources (typically an authentication or configuration problem), stop immediately. Tell the user this skill requires the Atlassian MCP server to be installed, configured, and authenticated, and that they can re-run the skill once it is connected.
If more than one cloud / site is accessible, note which sites are available; you will confirm the correct one while resolving the location in Step 2.
Resolve the Markdown file path from the arguments or conversation. Read it and confirm it exists and has content. If no file path was provided, or the path does not resolve to a readable file, ask the user for the path with AskUserQuestion and do not proceed without one. This is the exact content that will be posted; do not rewrite, summarize, or restructure it.
A body may legitimately contain embedded Confluence storage macros mixed into the Markdown — for example, an orchestrating skill such as han-atlassian:plan-a-feature-to-confluence rewrites its cross-page links into title-based page-link macros (the <ac:link><ri:page ri:content-title="..."/>…</ac:link> form, link body included) before handing the file over. Post these verbatim along with the rest of the body; do not strip or escape them.
This skill does not search Confluence for the right place. A typical Confluence instance is large and full of duplicate or similarly-named pages, so guessing the destination is unreliable. The user must name the exact location.
either of:
under it), or
URL).
AskUserQuestion torequest it, and explain plainly that the skill needs an exact destination because it does not search Confluence. Offer both accepted forms (a page URL, or a space plus parent page). This is required: do not proceed without a location.
cloud ID from Step 0 for every call.
/pages/<id>/ segment andcall mcp__claude_ai_Atlassian__getConfluencePage to confirm it exists and to read its space and title. Then determine the intent: update that page, or create a new child page under it. If the user did not already say, ask with AskUserQuestion.
mcp__claude_ai_Atlassian__getConfluenceSpaces to resolve the space ID from the key or name. If a parent page was named, find it with mcp__claude_ai_Atlassian__getPagesInConfluenceSpace or mcp__claude_ai_Atlassian__getConfluencePageDescendants (or by page ID/URL) to get the parent page ID. With no parent, the new page is created at the space root.
page ID (if any), existing page ID (if updating), the mode (create a new page, or update an existing one), and the intended page title. If updating, default the title to the existing page's title unless the user asked to rename it.
The publish mode controls whether the page goes live or is saved as an unpublished draft.
draft or live), use it. A callerthat already confirmed the choice with the user (such as han-atlassian:project-documentation-to-confluence) passes the mode through; do not ask again.
unintentionally. The user can re-run for live, or you may confirm with AskUserQuestion whether to save a draft (recommended default) or publish live now.
Read the Markdown file from Step 1 and publish it with the Atlassian MCP server. The Confluence MCP tools accept Markdown directly via contentFormat: "markdown", so post the document body as-is — no manual conversion to storage/XHTML is needed. Any embedded storage macros (such as the ac:link page-link macros described in Step 1) ride along in the same body; post them verbatim.
Apply the publish mode from Step 3 with the create/update tool's status parameter: draft → status: "draft" (unpublished draft), live → status: "current" (immediately visible). Confirm the exact field against the tool's input schema when you call it, and use whatever the tool exposes for draft-vs-published.
mcp__claude_ai_Atlassian__createConfluencePage with thecloud ID, space ID, title, the markdown body, contentFormat: "markdown", the chosen status ("draft" or "current"), and the parent page ID when one was resolved.
mcp__claude_ai_Atlassian__getConfluencePage first toread the current page (for its version and existing content), then call mcp__claude_ai_Atlassian__updateConfluencePage with the cloud ID, page ID, title, the markdown body, contentFormat: "markdown", and the chosen status. If the user chose draft for a page that is already published and the tool cannot hold an unpublished draft over a live page, do not silently publish it live: tell the user, and ask whether to publish the update live or keep the changes local only.
Diagram note: Markdown produced by Han's documentation skills emits Mermaid diagrams in fenced ``mermaid`` code blocks. Confluence does not render Mermaid natively without a Mermaid macro, so these blocks publish as code, not rendered diagrams. Leave them intact — do not silently strip them — and tell the user the diagrams posted as Mermaid source, in case their space has a macro that renders them or they want to convert them by hand.
On success, report the created or updated page's URL, and state whether it was published live or saved as a draft. For a draft, make clear the user still needs to review and publish it in Confluence. On failure, report the error and confirm the source Markdown file is unchanged and intact.
stopped before doing any work.
from an automated Confluence search.
(live or draft) and its URL was returned.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.