jenkins-ci
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: Most Jenkins CLI/API and pipeline examples are coherent with the stated CI/CD purpose and use official Jenkins endpoints. The main risk is the MCP integration: it instructs installation of an unverified npm executable not matching upstream distribution docs, then forwards Jenkins credentials to it. Combined with broad admin/deployment capabilities, this makes the skill high-risk even without clear evidence of malicious intent.
Confidence: 90%Severity: 84%
Audit Metadata