github-jira

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align for JIRA/GitHub project management, and data flows go to official Atlassian endpoints. However, core functionality relies on a non-official third-party jira CLI, one install path has mismatched publisher provenance, and the skill forwards JIRA credentials to that external tool while recommending persistent token storage. This is more risky than a pure documentation skill, but not fundamentally incompatible with its stated purpose.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:27 PM
Package URL
pkg:socket/skills-sh/vmvarela%2Fskills%2Fgithub-jira%2F@5eae17678904d45c595a9bab0b27ea952882441c