jenkins-cli

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but its actual footprint is not proportionate. It hardcodes a third-party Jenkins host for binary download, persists API tokens in plaintext shell files, and forwards credentials to an unverified JAR instead of following Jenkins' documented pattern of downloading the CLI from the target controller and using safer auth handling.

Confidence: 94%Severity: 90%
Audit Metadata
Analyzed At
Apr 4, 2026, 07:07 AM
Package URL
pkg:socket/skills-sh/cruldra%2Fskills%2Fjenkins-cli%2F@138f004dffc30e48e4c64f17747c0ab531a16051