jira-issue-to-pr

Warn

Audited by Socket on Aug 14, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/main.py

No clear evidence of overt malware (no eval/exec, no process spawning, no local credential harvesting beyond fetching an intended Jira token from a configured secrets service, no cryptomining/backdoor). The main security concern is that Jira issue content (including ADF description) is directly embedded into an instruction prompt sent to an internal agent with confirmation_policy=NeverConfirm, enabling potential prompt-injection/automation abuse if Jira content is attacker-controlled. Additionally, the workflow may clone repositories referenced in Jira descriptions, which is a supply-chain-adjacent risk if repository targets are not validated/sandboxed downstream.

Confidence: 66%Severity: 62%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose matches its Jira-to-GitHub automation behavior, and there is no obvious malicious installer or third-party credential sink. However, it enables autonomous PR creation and Jira commenting from untrusted ticket content, with repo selection taken from the ticket body and powerful inherited agent/GitHub access, making it a high-impact automation with meaningful abuse risk.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Aug 14, 2026, 12:08 PM
Package URL
pkg:socket/skills-sh/openhands%2Fextensions%2Fjira-issue-to-pr%2F@4b93395591fcb4a46ace8330c8dd8731c5c0a2c2df1ec57e13f8ae496a43171c
Security Audit — socket — jira-issue-to-pr