_index-rovo-agents

_index-rovo-agents is a cursor rule for Cursor from atlassian/forge-skills. It costs 0 tokens per session (643 once invoked), scanned A, original, Apache-2.0.

An automatically attached rules index for Forge Rovo agents, focusing on security risks in Atlassian Forge agents, their actions, and language-model-driven behavior.

In plain words
What is it for?
Use it when developing or reviewing Forge Rovo agents to find relevant rules for authorization, prompt-output injection, generated URLs, browser context, and app access restrictions.
Why use it?
It highlights risks such as excessive privileges, unsafe generated URLs, server-side request forgery, and unintended cross-product access.

Cursor rule for Cursor ✓ vendor

Written for Cursor: a Cursor rule (.mdc).

Good fit Use it when developing or reviewing Forge Rovo agents to find relevant rules for authorization, prompt-output injection, generated URLs, browser context, and app access restrictions.

Compare 6 cursor rules from other repositories ↓
Install with agentmods
npx agentmods add rules/atlassian/forge-skills/_index-rovo-agents
About the project

Atlassian Forge Skills supports Atlassian Forge, a platform for building and deploying apps that extend products such as Jira and Confluence. Its skills and MCP-backed tools help coding agents create Forge apps, review them before deployment, optimize usage, troubleshoot failures, and work with Forge APIs and the Atlassian Design System.

atlassian/forge-skills · 21 stars · on GitHub · developer.atlassian.com

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Clone the repo
git clone --depth 1 https://github.com/atlassian/forge-skills

Made for: Cursor.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for _index-rovo-agents

README.md
[![agentmods](https://agentmods.dev/badge/rules/atlassian/forge-skills/_index-rovo-agents.svg)](https://agentmods.dev/rules/atlassian/forge-skills/_index-rovo-agents)
Your own site
<a href="https://agentmods.dev/rules/atlassian/forge-skills/_index-rovo-agents"><img src="https://agentmods.dev/badge/rules/atlassian/forge-skills/_index-rovo-agents.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 643 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.00643
Opus 5 $0.00000 $0.00321
Sonnet 5 $0.00000 $0.00129
Haiku 4.5 $0.00000 $0.00064

Measured 8d ago against content hash 7605c28443a9, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

_index-rovo-agents scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/forge-security-review/assets/security-rules/forge-rovo-agents/_index-rovo-agents.mdc · 70 lines

What it actually says

  • Scope: Security considerations specific to Forge Rovo agents, actions, and LLM-driven functionality.
  • Priority: Emerging attack surface with unique privilege escalation and injection risks.

Key Forge Rovo Agent Risks

  • A4J running with elevated privileges: Agents executing actions with asApp() without proper authorization checks.
  • Known AuthZ gap (AGRC-15320): Agents can execute actions with higher privileges than intended.
  • LLM-generated URL risks: SSRF and data egress when agents render or fetch LLM-generated URLs.
  • Browser context consumption: Agents consuming user-controlled browser context URLs.
  • Cross-site/cross-product access: Custom agents providing unintended access across products.
  • App access rules bypass: Forge agents may not respect app access restriction rules.

Subrules

  • Agent Privilege Escalation → @forge-rovo-agents/agent-privilege-escalation.mdc
  • LLM Output Injection → @forge-rovo-agents/llm-output-injection.mdc
  • Prefer Using Function Context Object → @forge-authn-authz/prefer-context-authz.mdc
    • Use this rule if any agents have declared actions keys under modules.rovo:agent entries in their manifest

Detection Heuristics

  • Identify Rovo action modules in manifest and their associated functions.
  • Check for asApp() usage in agent actions without explicit permission validation.
  • Look for URL handling from LLM outputs without validation.
  • Review agent configurations for cross-product scope declarations.

Rovo-Specific Caveats

  • Rovo Forge Actions documentation lacks guidance on asUser vs asApp (unlike regular Forge Actions).
  • Authorization checks must happen before Forge function invocation; Convo AI should not allow unauthorized actions on restricted content.
  • Browser context URLs are user-controlled and must not be trusted.

Agent Authorization Pattern

// INSECURE - asApp without checks
export async function agentAction(payload) {
  const api = asApp();
  await api.requestJira(route`/rest/api/3/issue/${payload.issueId}`);
}

// SECURE - verify permissions first
export async function agentAction(payload, context) {
  // Verify the requesting user has permission
  const hasPermission = await checkUserPermission(context.accountId, payload.issueId);
  if (!hasPermission) {
    throw new Error('Unauthorized');
  }
  const api = asApp();
  await api.requestJira(route`/rest/api/3/issue/${payload.issueId}`);
}

CWE References

  • CWE-862: Missing Authorization
  • CWE-918: Server-Side Request Forgery
  • CWE-74: Improper Neutralization of Special Elements (Injection)
  • CWE-269: Improper Privilege Management
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 70 lines · 0 tokens per session scan A 7605c28443a9

Subscribe to this mod's changes

_index-rovo-agents is a cursor rule published in the GitHub repository atlassian/forge-skills (21 stars, last pushed 2d ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 643 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.