Hi everyone,
I’m working on validating an idea for a Rovo-style agent that could help detect and remediate accidentally exposed secrets (like API keys or credentials) across Atlassian products, specifically Bitbucket, Jira, and Confluence.
The agent would:
Detect secrets in commits, Confluence pages, attachments, and Jira ticket bodies
Validate whether the secrets are active (e.g., test against API endpoints)
Suggest remediation, like:
Auto-generating a PR to remove/replace secrets in code
Redacting secrets from Confluence while preserving version history
Flagging attachments or ticket fields with exposed data
Require manual review before any changes are applied
Would this be useful in your org?
Would you trust an agent like this with remediation suggestions?
Any tools you currently use for this?
Open to all feedback, trying to understand real-world need before building this as a Forge or Rovo agent.