jira-todo

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Jira Todo skill appears coherent with its stated purpose: it analyzes Jira ticket data via jira-cli, prioritizes work, and outputs a structured plan along with a to-do tracking step. The footprint is proportionate (local config access, Jira CLI interaction, and TodoWrite updates) and does not display dangerous data flows or credential-forwarding patterns. The main risks are typical for developer tooling (local credential access, dependency on jira-cli, and local config exposure) but there are no indicators of external data exfiltration or unverified binary installation. Overall, the skill is BENIGN with MEDIUM-low security risk due to local credential/config access and reliance on a trusted CLI tool.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:19 PM
Package URL
pkg:socket/skills-sh/mgiovani%2Fcc-arsenal%2Fjira-todo%2F@eb08d9246f1e33eb71a132332c41cdd785e6561d