jira-integration

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Jira capabilities match the stated purpose and the direct REST path is coherent and points to official Atlassian endpoints. Risk comes from the recommended MCP option: it installs and runs a third-party PyPI package and forwards Jira credentials into it, even though an official Atlassian MCP server exists. This is not confirmed malicious, but it is a meaningful trust and credential-forwarding concern.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Apr 14, 2026, 12:19 AM
Package URL
pkg:socket/skills-sh/Jord5s%2Feverything-claude-code%2Fjira-integration%2F@a492621aa0b1f3c90cb050108db8fa3cfe30874c
Security Audit — socket — jira-integration