I want to raise an important issue I encountered while using the Rovodev CLI from Atlassian.
Despite my repeated efforts to restrict its scope, the CLI continued to gather data from my entire local machine, not just the project directory I was working in. It persistently searched outside my working folder — even diving into sensitive directories like those named “products” — indexing every file name it could access. Re-issuing instructions to adhere to the task at hand, rovodev continued to index folders throughout my system (after being given explicit instructions to stay in the projects working directory).
Even more concerning:
The CLI explicitly admitted that information about these indexed files had been sent (indirectly) to Atlassian systems. That means even folders completely unrelated to my project were scanned and reported — something I never consented to.
This is a serious breach of developer trust. Tools like this should never index or transmit data from outside of the defined project scope — especially not without clear consent or explicit user configuration.
If you're using Rovodev CLI, I strongly recommend:
Running it in an isolated, sandboxed environment.
Monitoring its network activity.
Keeping an eye on what directories it's accessing.
Atlassian needs to clarify and rectify this behavior immediately. Transparency and user control are non-negotiable in developer tooling.
—
Stay secure. Stay aware.