jira

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated Jira purpose matches its capabilities, and the npm CLI appears to have reasonable same-org provenance, so this is not confirmed malware. However, all Jira access is brokered through ClawLink’s hosted service rather than official Atlassian APIs, creating a disproportionate third-party data and credential trust layer with meaningful write-action capability.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fjira%2F@b9fa8b918b163106949ece954dd1fd10cbe1f885fa4210ee083fcb246831003e
Security Audit — socket — jira