Agent skill

Jira Issues By Component

by openshift-eng in openshift-eng/ai-helpers

Provides secure curl wrapper for the jira:issues-by-component command to prevent token exposure

Apache-2.0Auto-check passed

Install Jira Issues By Component

skills CLI
$ npx skills add openshift-eng/ai-helpers --skill jira-issues-by-component -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openshift-eng/ai-helpers jira-issues-by-component --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openshift-eng/ai-helpers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/jira/skills/jira-issues-by-component .claude/skills/jira-issues-by-component && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
jira-issues-by-component
GitHub stars
120
Token cost
~1.5k tokens
SKILL.md length
436 words
Files
3
Skills in repo
118
Repo updated
First seen
Licence
Apache-2.0

At a glance

Provides secure curl wrapper for the jira:issues-by-component command to prevent token exposure

  • Works in 4 steps: Token Protection: Authentication tokens… → History Safety: Tokens are not saved in… → Process Isolation: Token is read from… → …
  • SKILL.md covers When to Use This Skill, Security Benefits, Files and How It Works, plus 7 more sections
  • Runs Shell scripts from its folder; calls curl; reaches redhat.atlassian.net and id.atlassian.com; needs JIRA_API_TOKEN and AUTH_TOKEN

What it does

Jira Issues By Component is an agent skill from openshift-eng/ai-helpers. Provides secure curl wrapper for the jira:issues-by-component command to prevent token exposure

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `README.md` and `jira_curl.sh`).

It works with Jira. The repository describes itself as: Developer productivity tools for Claude Code & other AI assistants. The licence is Apache-2.0.

Example prompts

  • “Use the jira-issues-by-component skill to provide secure curl wrapper for the jira:issues-by-component command to prevent token exposure”
  • “/jira-issues-by-component”

Requirements

  • A Bash shell
  • A credential in JIRA_API_TOKEN
  • A credential in AUTH_TOKEN

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Token Protection: Authentication tokens never appear in process listings (ps aux)
  2. History Safety: Tokens are not saved in shell history files
  3. Process Isolation: Token is read from environment variables inside the script
  4. Clean Interface: Same curl arguments you're already familiar with

What it can do on your machine

Read from SKILL.md and the folder at commit a627176. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • redhat.atlassian.net
    • id.atlassian.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JIRA_API_TOKEN
    • AUTH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Jira Issues By Component loads about 1.5k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 436 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openshift-eng/ai-helpers at commit a627176, republished under its Apache-2.0 licence (© openshift-eng). 436 words, ~1,526 tokens.

Download SKILL.mdSave it as .claude/skills/jira-issues-by-component/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
jira-issues-by-component
description
Provides secure curl wrapper for the jira:issues-by-component command to prevent token exposure

JIRA Issues by Component - Helper Skill

This skill provides a secure curl wrapper script for the jira:issues-by-component command. The wrapper prevents JIRA authentication token exposure in process listings and command history.

When to Use This Skill

This skill is automatically used by the jira:issues-by-component command. You typically don't need to invoke it directly unless you're:

  • Developing or testing JIRA API integrations
  • Building custom JIRA scripts that need secure authentication
  • Debugging JIRA API connectivity issues

Security Benefits

The jira_curl.sh wrapper script provides:

  1. Token Protection: Authentication tokens never appear in process listings (ps aux)
  2. History Safety: Tokens are not saved in shell history files
  3. Process Isolation: Token is read from environment variables inside the script
  4. Clean Interface: Same curl arguments you're already familiar with

Files

jira_curl.sh

Secure curl wrapper that automatically adds JIRA authentication headers.

Location: plugins/jira/skills/jira-issues-by-component/jira_curl.sh

Usage:

bash
jira_curl.sh [curl arguments...]

Required Environment Variables:

  • JIRA_URL: JIRA instance URL (e.g., https://redhat.atlassian.net)
  • JIRA_API_TOKEN: Authentication token
  • JIRA_USERNAME: Atlassian account email for Basic auth

Example:

bash
# Set credentials
export JIRA_URL="https://redhat.atlassian.net"
export JIRA_API_TOKEN="your-token-here"
export JIRA_USERNAME="user@redhat.com"

# Use wrapper (token hidden from process list)
jira_curl.sh -s -X POST -d '{"jql":"project=OCPBUGS"}' https://redhat.atlassian.net/rest/api/3/search/jql

How It Works

  1. Environment Check: Validates that JIRA_URL and authentication token are set
  2. Token Selection: Uses JIRA_API_TOKEN for Atlassian Cloud authentication
  3. Header Injection: Constructs Authorization: Basic <base64> header inside the script using JIRA_USERNAME and JIRA_API_TOKEN
  4. Process Replacement: Uses exec curl to replace the script process with curl
  5. Clean Execution: Token never crosses process boundaries as a visible argument

Implementation Details

The wrapper uses the same security pattern as the oc auth skill:

bash
# Token and username are read from environment variables inside the script
AUTH_TOKEN="${JIRA_API_TOKEN:-}"
JIRA_USER="${JIRA_USERNAME:-}"

# Execute curl with Basic authentication header
# Credentials are constructed here, never visible in parent process command line
AUTH_HEADER=$(printf '%s:%s' "$JIRA_USER" "$AUTH_TOKEN" | base64)
exec curl -H "Authorization: Basic $AUTH_HEADER" -H "Accept: application/json" "$@"

Why exec?

  • Replaces the script process with curl process
  • By the time curl runs, the wrapper script is gone
  • Only curl appears in process listings, not the wrapper with token
Show full SKILL.md (169 more words)Show less

Error Handling

The script provides clear error messages for common scenarios:

Missing JIRA_URL:

Error: JIRA_URL environment variable is required

Please set JIRA credentials:
  export JIRA_URL='https://redhat.atlassian.net'
  export JIRA_API_TOKEN='your-token-here'

Alternatively, source a credentials file:
  source ~/.jira-credentials

Missing Token:

Error: JIRA authentication token is required

Please set:
  export JIRA_API_TOKEN='your-token-here'
  export JIRA_USERNAME='user@redhat.com'

Get your token from:
  - Atlassian API Token: https://id.atlassian.com/manage-profile/security/api-tokens

Credentials Setup

Option 1: Export Directly
bash
export JIRA_URL="https://redhat.atlassian.net"
export JIRA_API_TOKEN="your-token-here"
export JIRA_USERNAME="user@redhat.com"

Create ~/.jira-credentials:

bash
# ~/.jira-credentials
export JIRA_URL="https://redhat.atlassian.net"
export JIRA_API_TOKEN="your-token-here"
export JIRA_USERNAME="user@redhat.com"

Secure the file:

bash
chmod 600 ~/.jira-credentials

Source it when needed:

bash
source ~/.jira-credentials

Getting Your Token

Atlassian Cloud (API Token)
  1. Visit: https://id.atlassian.com/manage-profile/security/api-tokens
  2. Click "Create API token"
  3. Give it a label (e.g., "CLI Access")
  4. Copy the token
  5. Set as JIRA_API_TOKEN

Comparison to Direct Curl

Insecure Approach (Don't Do This)
bash
# Credentials exposed in process list and history!
curl -u "user@redhat.com:${JIRA_API_TOKEN}" -X POST \
  -H "Content-Type: application/json" \
  -d '{"jql":"..."}' \
  https://redhat.atlassian.net/rest/api/3/search/jql

Problems:

  • ❌ Token visible in ps aux
  • ❌ Token saved in shell history
  • ❌ Token may appear in logs
  • ❌ Security risk
Secure Approach (Use This)
bash
# Token hidden inside wrapper script
jira_curl.sh -X POST -H "Content-Type: application/json" \
  -d '{"jql":"..."}' https://redhat.atlassian.net/rest/api/3/search/jql

Benefits:

  • ✅ Token never in process list
  • ✅ Token never in shell history
  • ✅ Clean and simple syntax
  • ✅ Secure by design

Integration with jira:issues-by-component

The jira:issues-by-component command uses this wrapper to fetch JIRA issues securely:

bash
# Get path to secure curl wrapper
PLUGIN_DIR="plugins/jira/skills/jira-issues-by-component"
JIRA_CURL="${PLUGIN_DIR}/jira_curl.sh"

# Fetch issues with pagination (token hidden)
HTTP_CODE=$("$JIRA_CURL" -s -w "%{http_code}" \
  -o "batch-${BATCH_NUM}.json" \
  "${API_URL}")

This approach:

  • Handles 2000+ issues efficiently
  • Streams data directly to disk
  • Never exposes authentication token
  • Avoids LLM token consumption

See Also

© openshift-eng, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in plugins/jira/skills/jira-issues-by-component of openshift-eng/ai-helpers.

  • SKILL.md
  • README.md
  • jira_curl.sh

Open the folder on GitHubat commit a627176

Compare with similar skills

Jira Issues By Component next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Jira Issues By Component compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Jira Issues By Component this skillopenshift-eng/ai-helpers120—~1.5kAutomated safety check: PassApache-2.0
Management Talkthananon/9arm-skills3.2k—~3.2kAutomated safety check: PassNone
YugabyteDB Issue Creatoryugabyte/yugabyte-db11k—~2kAutomated safety check: PassCustom licence
Dynamo Jira TicketDynamoDS/Dynamo2k—~1.1kAutomated safety check: PassApache-2.0
Code Reviewcroffasia/itsaplan903—~2kAutomated safety check: PassAGPL-3.0
Connect Apps with ComposioComposioHQ/awesome-claude-skills77k3 repos~557Automated safety check: PassNone

Similar skills

  • Management Talk

    thananon/9arm-skills

    Rewrite engineer-to-engineer content for engineering-org leadership (VPs, directors, PMs, release managers, execs in an engineering-savvy company) and shape it for the channel it is going to — JIRA…

    3.2k GitHub stars~3.2k tokensUpdated 3 mo ago
    Productivity & AutomationAuto-check passed
  • YugabyteDB Issue Creator

    yugabyte/yugabyte-db

    Creates a GitHub issue or JIRA ticket for a YugabyteDB change or bug, after scrubbing customer data, secrets and unreleased details from anything public.

    11k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Dynamo Jira Ticket

    DynamoDS/Dynamo

    Create structured Jira tickets for Dynamo from bug reports, failing tests, or feature requests.

    2k GitHub stars~1.1k tokensUpdated today
    Testing & QAAuto-check passed
  • Code Review

    croffasia/itsaplan

    A skill your agent uses when reviewing code — a diff, a merge request, a file, a directory, or a feature.

    903 GitHub stars~2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Connect Apps with Composio

    ComposioHQ/awesome-claude-skills

    Connects an agent to 1000+ external apps through the Composio Tool Router plugin, so it can actually send emails, create issues and post messages instead of only drafting them.

    77k GitHub starsUsed in 3 repos~557 tokens
    Productivity & AutomationAuto-check passed
  • PR Body

    SAP/spartacus

    Official

    A skill your agent uses when the user asks to generate, write, or draft a pull request (PR) body or description for the current branch.

    784 GitHub stars~499 tokensUpdated today
    DevelopmentAuto-check passed

More from openshift-eng/ai-helpers

All 118 skills in this repo
  • Investigate CI Reliability

    openshift-eng/ai-helpers

    Find and independently validate actionable reliability defects across OpenShift release jobs and presubmits, then export portable issue handoffs.

    120 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Address Review PR

    openshift-eng/ai-helpers

    Fetch and address all PR review comments — categorize by priority, make code changes, post replies, and push.

    120 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Categorize Activity Types

    openshift-eng/ai-helpers

    Categorize Jira issues into Red Hat Sankey Activity Type categories using MCP Jira tools.

    120 GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Has Review Work

    openshift-eng/ai-helpers

    Decide whether a GitHub PR has unanswered authorized review comments or new required CI failures worth a follow-up agent.

    120 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Must Gather Analyzer

    openshift-eng/ai-helpers

    Analyze OpenShift must-gather diagnostic data including cluster operators, pods, nodes, and network components.

    120 GitHub stars~2.3k tokensUpdated 2 days ago
    Auto-check passed
  • Payload Autodl JSON

    openshift-eng/ai-helpers

    Schema for the autodl JSON data file produced by payload-analysis for database ingestion — you must use this skill whenever generating the autodl JSON file

    120 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Jira Issues By Component

What does Jira Issues By Component do?

Provides secure curl wrapper for the jira:issues-by-component command to prevent token exposure. Jira Issues By Component is an agent skill from openshift-eng/ai-helpers.

How do I install Jira Issues By Component in Claude Code?

Run `npx skills add openshift-eng/ai-helpers --skill jira-issues-by-component -a claude-code`. Or copy the skill folder (plugins/jira/skills/jira-issues-by-component in openshift-eng/ai-helpers) into .claude/skills/jira-issues-by-component in your project. Claude Code loads it when a task matches its description.

How do I install Jira Issues By Component in Codex?

Run `npx skills add openshift-eng/ai-helpers --skill jira-issues-by-component -a codex`. Or copy the skill folder (plugins/jira/skills/jira-issues-by-component in openshift-eng/ai-helpers) into .agents/skills/jira-issues-by-component in your project. Codex loads it when a task matches its description.

Can I use Jira Issues By Component in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openshift-eng/ai-helpers --skill jira-issues-by-component -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/jira-issues-by-component, .gemini/skills/jira-issues-by-component, .github/skills/jira-issues-by-component and .opencode/skills/jira-issues-by-component in your project.

What does Jira Issues By Component need to run?

Going by SKILL.md and its folder, Jira Issues By Component needs a shell for the scripts in its folder, the command-line tools its instructions call (curl) and credentials named JIRA_API_TOKEN and AUTH_TOKEN. Our summary lists: A Bash shell; A credential in JIRA_API_TOKEN; A credential in AUTH_TOKEN.

Does Jira Issues By Component access the network?

SKILL.md names 2 domains. In commands or code: redhat.atlassian.net and id.atlassian.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Jira Issues By Component safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Jira Issues By Component use?

Jira Issues By Component is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Jira Issues By Component use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Jira Issues By Component?

Skills that share tags, products or a category with Jira Issues By Component: Management Talk (thananon/9arm-skills, 3.2k stars), YugabyteDB Issue Creator (yugabyte/yugabyte-db, 11k stars), Dynamo Jira Ticket (DynamoDS/Dynamo, 2k stars) and Code Review (croffasia/itsaplan, 903 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Jira Issues By Component?

openshift-eng (a GitHub organization) maintains it in openshift-eng/ai-helpers, which has 120 GitHub stars. The repository holds 118 skills in this directory. The repository was last updated on October 6, 2026.

Source: openshift-eng/ai-helpers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.