jira-integration

Warn

Audited by Socket on Jun 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Jira capabilities match the stated purpose and the direct REST path is coherent and points to official Atlassian endpoints. Risk comes from the recommended MCP option: it installs and runs a third-party PyPI package and forwards Jira credentials into it, even though an official Atlassian MCP server exists. This is not confirmed malicious, but it is a meaningful trust and credential-forwarding concern.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Jun 24, 2026, 12:59 PM
Package URL
pkg:socket/skills-sh/tusharkrbarman%2Fskills-for-open-code%2Fjira-integration%2F@b51805b95c45f137b68c65023c4427260a2b90a5a3b1c892d4061f6c8423c316
Security Audit — socket — jira-integration