jira-integration

Warn

Audited by Socket on Aug 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The direct REST usage is coherent and low-risk, but the recommended path forwards Jira credentials to a non-Atlassian third-party MCP package. That is proportionate to the skill’s purpose yet creates medium supply-chain and credential-forwarding risk without evidence of outright malicious behavior.

Confidence: 89%Severity: 61%
Audit Metadata
Analyzed At
Aug 29, 2026, 03:15 AM
Package URL
pkg:socket/skills-sh/affaan-m%2Fecc%2Fjira-integration%2F@e53518853c9044f900a38ed36fe7fb76a8256fd1b7462602cfb02a3264b383ca
Security Audit — socket — jira-integration