Jira Access

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's code and README clearly require Jira credentials (domain, email, API token) but the registry metadata lists no required credentials — the mismatch and unknown source are concerning even though the code itself matches the stated Jira purpose.

This skill's code and README expect you to provide a Jira domain, email, and API token, but the registry metadata incorrectly shows no required credentials — that mismatch is the main concern. Before installing, verify the skill's origin and owner, and prefer these mitigations: (1) only supply a token scoped to the minimum permissions needed (prefer a dedicated service account), (2) do not use your primary personal Atlassian token, (3) store secrets in the platform's secret store or a CI secret, not in plaintext, (4) review the included scripts locally to confirm no unexpected behavior, and (5) if you don't control the referenced Jira domain (omeshkshatriya.atlassian.net) do not provide credentials. If you need higher assurance, ask the publisher to correct the registry metadata to declare required env vars and to provide a verifiable source/homepage.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

No VirusTotal findings

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.