krt-jira-cloud-scribe

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run_with_jira_env.py

This module is a sensitive command-execution wrapper: it validates and loads secret-derived environment variables from a file under a user-chosen root, then executes an arbitrary caller-supplied command with those environment variables. In this fragment there is no explicit evidence of overt malware behaviors (network access, persistence, or file system damage), and no obfuscation. However, the design is inherently high-impact in supply-chain/CI contexts because it enables arbitrary child process execution and propagates potentially sensitive environment data; additionally, error paths may disclose diagnostic information (including loaded_vars) and the secret-handling behavior is delegated to an external dependency not shown here. Overall, treat as a moderate-to-high security-risk utility that should be used only in trusted automation contexts with controlled inputs.

Confidence: 58%Severity: 58%
Audit Metadata
Analyzed At
Aug 12, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/elzawarudo%2Fkrt%2Fkrt-jira-cloud-scribe%2F@335b97b86ab42e6b1127b9a839d7ca5d4fb2e14fb797d6efb561cbb027b7c6c4
Security Audit — socket — krt-jira-cloud-scribe