jira-automation

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's Jira purpose is plausible, but its actual data flow is through a third-party MCP/gateway (Rube/Composio) instead of official Atlassian endpoints, and it enables broad write-capable Jira actions. This is not confirmed malware, but it is a medium-high risk integration because organizational data and OAuth-backed operations are mediated by an external service with broad scope.

Confidence: 83%Severity: 68%
Audit Metadata
Analyzed At
Mar 30, 2026, 06:13 PM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fjira-automation%2F@f2b0e5cbfceaecddcb3066ace1304de6adcb0a9e