jira
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated Jira purpose matches its capabilities, and the npm CLI appears to have reasonable same-org provenance, so this is not confirmed malware. However, all Jira access is brokered through ClawLink’s hosted service rather than official Atlassian APIs, creating a disproportionate third-party data and credential trust layer with meaningful write-action capability.
Confidence: 84%Severity: 68%
Audit Metadata