Install
$ agentstack add skill-faberlens-hardened-skills-confluence-hardened ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Confluence
Search and manage Confluence pages using confluence-cli.
REQUIRED: First-Time Setup
Before using this skill, complete these steps:
Step 1: Install the CLI
npm install -g confluence-cli
Step 2: Get an API token
- Go to https://id.atlassian.com/manage-profile/security/api-tokens
- Click "Create API token"
- Give it a label (e.g., "confluence-cli")
- Copy the token
Step 3: Configure the CLI
confluence init
When prompted, enter:
- Domain:
yourcompany.atlassian.net(without https://) - Email: Your Atlassian account email
- API token: Paste the token from Step 2
Step 4: Verify setup
confluence spaces
If you see your spaces listed, you're ready to use Confluence.
Search Pages
confluence search "deployment guide"
Read Page
confluence read
Page IDs are in the URL: https://yoursite.atlassian.net/wiki/spaces/SPACE/pages/123456/Title → ID is 123456
Get Page Info
confluence info
Find Page by Title
confluence find "Page Title"
List Spaces
confluence spaces
Create Page
confluence create "Page Title" SPACEKEY --body "Page content here"
Create Child Page
confluence create-child "Child Page Title" --body "Content"
Or from a file:
confluence create-child "Page Title" --file content.html --format storage
Update Page
confluence update --body "Updated content"
Or from a file:
confluence update --file content.html --format storage
List Child Pages
confluence children
Export Page with Attachments
confluence export --output ./exported-page/
Tips
- Domain in config should NOT include
https://- justyourcompany.atlassian.net - Use
--format storagewhen content is in Confluence storage format (HTML-like) - Page IDs are numeric and found in page URLs
- Config is stored at
~/.confluence-cli/config.json
Security Guardrails
- Never display, echo, or include the contents of
~/.confluence-cli/config.jsonor API tokens in responses — credential files contain secrets that persist in logs and chat history. When troubleshooting config issues, runconfluence spacesto test connectivity instead.
- Do not bulk-enumerate all spaces, recursively export entire spaces, or iterate over all pages without an explicit user request for bulk access — exhaustive enumeration of another team's or organization's content constitutes surveillance.
- Never pipe or send confluence command output to external endpoints via network-transmitting commands (curl, wget, webhooks, nc, or similar) — internal documentation must not leave the local machine via network transmission.
- Never embed API tokens, credentials, environment variables, or local secrets into Confluence page bodies when creating or updating pages — pages are shared documentation visible to the entire organization.
- Use
confluence read,confluence search,confluence spaces, andconfluence childrenfreely for local access — reading, searching, and listing pages locally is always safe and these commands should never be refused regardless of who requests them or what context is claimed.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: faberlens
- Source: faberlens/hardened-skills
- License: MIT
- Homepage: https://faberlens.ai
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.