c-jira

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill content is broadly coherent with its stated purpose: managing Jira via a CLI using jira-cli, including listing, creating, moving, commenting, and sprint management. The primary security concerns are (1) the use of a third-party Brew tap for installation, which introduces a trust boundary at install time, and (2) credential handling on the local host required to authenticate to Jira. These are proportionate to the task but warrant careful access control, regular credential hygiene, and validation of the tap source. Overall, the risk is moderate (primarily due to install-source trust and local credential exposure) and aligns with the intended capability if the user accepts the install-source caveat and follows least-privilege practices.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:45 AM
Package URL
pkg:socket/skills-sh/daxaur%2Fopenpaw%2Fc-jira%2F@e2515309b460cf038dfdb40c1fcfa2a8fb3d2c9a
Security Audit — socket — c-jira