Back to plugin

Security audit

jirac Plugin

Security checks for vulnerabilities and agentic risk

Overview

This Jira skill pack is mostly coherent, but it gives agents broad Jira write and raw API authority with inconsistent confirmation guidance for bulk or destructive actions.

Install only if you are comfortable letting an agent use your Jira CLI credentials to read and modify Jira data, including bulk updates, comments, transitions, archives, deletes, sprint changes, attachments, and raw REST API calls. Use least-privilege Jira permissions, review generated JQL/manifests before execution, and require explicit confirmation for any non-GET, bulk, archive, delete, move, or --force operation.

Static analysis

No suspicious patterns detected.