jira-issue-manager

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s Jira-management purpose mostly matches its capabilities, and the Nango/Jira cloudId flow is consistent with official documentation. However, it relies on a third-party proxy, delegates auth to another skill, and asks the agent to pass a high-value Nango secret to local scripts whose contents were not provided. This is not confirmed malware, but it carries meaningful credential-handling and trust-chain risk.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
Apr 1, 2026, 07:06 PM
Package URL
pkg:socket/skills-sh/contextware%2Fskills%2Fjira-issue-manager%2F@d8ccac5642ee3fa486adfd55ca3c89dd1607622b