jira

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill is a Jira integration that intentionally routes Jira API calls and OAuth through Maton-managed endpoints and requires a MATON_API_KEY environment variable. Functionality aligns with the stated purpose (managed OAuth gateway), but the architecture centralizes credentials and all Jira traffic through a third-party (Maton), increasing trust surface and potential impact if Maton is compromised or malicious. There are no download-execute patterns or obvious backdoors in the provided fragment. Recommend that users treat MATON_API_KEY as a high-privilege secret, review Maton's privacy/security practices, and prefer direct Atlassian OAuth where organizational policy requires minimal third-party exposure.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 26, 2026, 10:31 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fjira%2F@ab7c0a91900a27127b2cd05dc01aa7ad263e1625