jira-cli

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
references/scripting.md

Best report selection: Report 1 is the most complete. Improved assessment: the code is primarily legitimate Jira automation, with no clear evidence of embedded malware (no backdoor/exfiltration/persistence). The primary security issue is the GitHub Actions step that downloads and installs a `jira-cli` binary from `releases/latest` using `wget` without pinning and without checksum/signature verification, which creates a significant supply-chain integrity risk. Secondary risk is shell parsing/quoting robustness that could lead to unintended Jira updates if values contain whitespace/newlines.

Confidence: 66%Severity: 52%
Audit Metadata
Analyzed At
Mar 26, 2026, 08:43 PM
Package URL
pkg:socket/skills-sh/mgiovani%2Fcc-arsenal%2Fjira-cli%2F@7a0370e9a8f41a49133d36409f8a4211567eea84