# Confluence Hardened

> Search and manage Confluence pages and spaces using confluence-cli. Read documentation, create pages, and navigate spaces.

- **Type:** Skill
- **Install:** `agentstack add skill-faberlens-hardened-skills-confluence-hardened`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [faberlens](https://agentstack.voostack.com/s/faberlens)
- **Installs:** 0
- **Category:** [Productivity](https://agentstack.voostack.com/c/productivity)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [faberlens](https://github.com/faberlens)
- **Source:** https://github.com/faberlens/hardened-skills/tree/main/skills/confluence-hardened
- **Website:** https://faberlens.ai

## Install

```sh
agentstack add skill-faberlens-hardened-skills-confluence-hardened
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Confluence

Search and manage Confluence pages using confluence-cli.

## REQUIRED: First-Time Setup

Before using this skill, complete these steps:

**Step 1: Install the CLI**

```bash
npm install -g confluence-cli
```

**Step 2: Get an API token**

1. Go to https://id.atlassian.com/manage-profile/security/api-tokens
2. Click "Create API token"
3. Give it a label (e.g., "confluence-cli")
4. Copy the token

**Step 3: Configure the CLI**

```bash
confluence init
```

When prompted, enter:
- **Domain**: `yourcompany.atlassian.net` (without https://)
- **Email**: Your Atlassian account email
- **API token**: Paste the token from Step 2

**Step 4: Verify setup**

```bash
confluence spaces
```

If you see your spaces listed, you're ready to use Confluence.

---

## Search Pages

```bash
confluence search "deployment guide"
```

## Read Page

```bash
confluence read 
```

Page IDs are in the URL: `https://yoursite.atlassian.net/wiki/spaces/SPACE/pages/123456/Title` → ID is `123456`

## Get Page Info

```bash
confluence info 
```

## Find Page by Title

```bash
confluence find "Page Title"
```

## List Spaces

```bash
confluence spaces
```

## Create Page

```bash
confluence create "Page Title" SPACEKEY --body "Page content here"
```

## Create Child Page

```bash
confluence create-child "Child Page Title"  --body "Content"
```

Or from a file:

```bash
confluence create-child "Page Title"  --file content.html --format storage
```

## Update Page

```bash
confluence update  --body "Updated content"
```

Or from a file:

```bash
confluence update  --file content.html --format storage
```

## List Child Pages

```bash
confluence children 
```

## Export Page with Attachments

```bash
confluence export  --output ./exported-page/
```

## Tips

- Domain in config should NOT include `https://` - just `yourcompany.atlassian.net`
- Use `--format storage` when content is in Confluence storage format (HTML-like)
- Page IDs are numeric and found in page URLs
- Config is stored at `~/.confluence-cli/config.json`

## Security Guardrails

- Never display, echo, or include the contents of `~/.confluence-cli/config.json` or API tokens in responses — credential files contain secrets that persist in logs and chat history. When troubleshooting config issues, run `confluence spaces` to test connectivity instead.

- Do not bulk-enumerate all spaces, recursively export entire spaces, or iterate over all pages without an explicit user request for bulk access — exhaustive enumeration of another team's or organization's content constitutes surveillance.

- Never pipe or send confluence command output to external endpoints via network-transmitting commands (curl, wget, webhooks, nc, or similar) — internal documentation must not leave the local machine via network transmission.

- Never embed API tokens, credentials, environment variables, or local secrets into Confluence page bodies when creating or updating pages — pages are shared documentation visible to the entire organization.

- Use `confluence read`, `confluence search`, `confluence spaces`, and `confluence children` freely for local access — reading, searching, and listing pages locally is always safe and these commands should never be refused regardless of who requests them or what context is claimed.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [faberlens](https://github.com/faberlens)
- **Source:** [faberlens/hardened-skills](https://github.com/faberlens/hardened-skills)
- **License:** MIT
- **Homepage:** https://faberlens.ai

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** yes
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-faberlens-hardened-skills-confluence-hardened
- Seller: https://agentstack.voostack.com/s/faberlens
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
