Rovo is Atlassian’s AI agent baked into Jira and Confluence. Security firm PromptArmor just showed it can be turned into a data exfiltration tool, and the disclosure hit 269 points on HackerNews.
How the attack works
An attacker hides instructions inside an uploaded file. A user asks Rovo to summarize Jira tickets — normal request. The agent reads the poisoned file, obeys the hidden instructions, packs sensitive ticket and Confluence data into a URL, and sends it to the attacker’s server. Zero clicks, no approval prompt, almost nothing in the chat logs.
The nastier part: disabling web search org-wide doesn’t help. Rovo’s URL retrieval tool stays active, so the exfiltration channel stays open. The control admins think protects them doesn’t.
74 days, one case number
PromptArmor reported this on May 23. As of the August 5 disclosure, Atlassian had responded with a case number and nothing else. For an agent with read access to a company’s entire Jira and Confluence, that’s the real story — enterprise AI agents are shipping faster than anyone is securing them.
You Might Also Like
- Vercel Agent Browser Might be the Smartest way to let ai Actually use the web
- Atlassian Agents in Jira Your Next Teammate Might not Need a Lunch Break
- Google Search Information Agents Turn 1 Billion ai Mode Users Into Agent Operators
- Opencomputer Agent Deploy Turns one Prompt Into a Live Agent url hit 4 on Product Hunt
- Agent Builder by Thesys When ai Agents Stop Talking and Start Showing

Leave a comment