jenkins-ci

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: Most Jenkins CLI/API and pipeline examples are coherent with the stated CI/CD purpose and use official Jenkins endpoints. The main risk is the MCP integration: it instructs installation of an unverified npm executable not matching upstream distribution docs, then forwards Jenkins credentials to it. Combined with broad admin/deployment capabilities, this makes the skill high-risk even without clear evidence of malicious intent.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 07:20 AM
Package URL
pkg:socket/skills-sh/phuetz%2Fcode-buddy%2Fjenkins-ci%2F@f0db718eeda8a5d3d778921fc2cb6dd96cd9f673
Security Audit — socket — jenkins-ci