jira-automation

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s Jira capabilities mostly match its stated purpose, but trust and data-flow boundaries are broader than the description implies. It routes Jira access through a third-party Composio/Rube MCP layer, uses managed OAuth/token storage, and references a discontinued/stale Rube setup path. This is not confirmed malware, but it is a medium-risk remote integration with real-world write actions and outdated setup guidance.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Jul 18, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/rohitg00%2Fbuildwithclaude%2Fjira-automation%2F@dc4a23504b1f3dd5a929cc531edec26e600e437030fe9e728059d3f61c466e96
Security Audit — socket — jira-automation