jenkins-cli
Warn
Audited by Socket on Apr 4, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is plausible, but its actual footprint is not proportionate. It hardcodes a third-party Jenkins host for binary download, persists API tokens in plaintext shell files, and forwards credentials to an unverified JAR instead of following Jenkins' documented pattern of downloading the CLI from the target controller and using safer auth handling.
Confidence: 94%Severity: 90%
Audit Metadata