jira-issue-to-pr
Audited by Socket on Aug 14, 2026
2 alerts found:
AnomalySecurityNo clear evidence of overt malware (no eval/exec, no process spawning, no local credential harvesting beyond fetching an intended Jira token from a configured secrets service, no cryptomining/backdoor). The main security concern is that Jira issue content (including ADF description) is directly embedded into an instruction prompt sent to an internal agent with confirmation_policy=NeverConfirm, enabling potential prompt-injection/automation abuse if Jira content is attacker-controlled. Additionally, the workflow may clone repositories referenced in Jira descriptions, which is a supply-chain-adjacent risk if repository targets are not validated/sandboxed downstream.
SUSPICIOUS: the skill’s purpose matches its Jira-to-GitHub automation behavior, and there is no obvious malicious installer or third-party credential sink. However, it enables autonomous PR creation and Jira commenting from untrusted ticket content, with repo selection taken from the ticket body and powerful inherited agent/GitHub access, making it a high-impact automation with meaningful abuse risk.