jira-automation

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities match Jira automation, but its trust model depends on a third-party MCP intermediary and the setup instructions are partly inconsistent with current official Composio documentation. This is not confirmed malware, but it carries medium risk because Jira data and OAuth-backed actions are brokered through hosted infrastructure outside Atlassian, and the referenced Rube endpoint appears transitional/shutting down.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 24, 2026, 08:01 PM
Package URL
pkg:socket/skills-sh/davila7%2Fclaude-code-templates%2Fjira-automation%2F@f2b0e5cbfceaecddcb3066ace1304de6adcb0a9e