jira-integration

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and core Jira capabilities are coherent, and the direct REST path is benign and properly aligned with official Atlassian APIs. However, the recommended MCP approach routes Jira credentials into a third-party package (mcp-atlassian) rather than an Atlassian-official server, creating avoidable credential-forwarding and supply-chain risk. No evidence of overt malware or unrelated exfiltration was found.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
Apr 4, 2026, 01:43 AM
Package URL
pkg:socket/skills-sh/affaan-m%2Feverything-claude-code%2Fjira-integration%2F@a492621aa0b1f3c90cb050108db8fa3cfe30874c