jira-integration

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and API actions are coherent for Jira integration, and the direct REST path is proportionate and points to official Jira endpoints. Risk comes from the recommended MCP path: it installs and entrusts Jira credentials to a third-party community package rather than an Atlassian-official component. No clear exfiltration, stealth, or malware behavior is shown, but the credential-forwarding and third-party execution trust issues make the skill medium/high risk overall.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Sep 1, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/defuj%2Fopencode-agent-kit%2Fjira-integration%2F@c727a3d0b7cbcf3ed2c9cb9ebd3c1bef33d14bd4e21ee8eedf0f9e015497a8b7
Security Audit — socket — jira-integration