jira

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities fit its Jira purpose, and the install path uses an official npm package rather than a raw download. However, all authentication and Jira access are mediated through Membrane’s third-party CLI/service instead of direct Atlassian APIs, creating moderate trust and data-flow risk; the unpinned `@latest` install and dynamic action creation add further caution.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fjira%2F@02967ef4750ab914e4423bc36bfe57ab1a1c19a9