Security audit
jirac Plugin
Security checks for vulnerabilities and agentic risk
Overview
This Jira skill pack is mostly coherent, but it gives agents broad Jira write and raw API authority with inconsistent confirmation guidance for bulk or destructive actions.
Install only if you are comfortable letting an agent use your Jira CLI credentials to read and modify Jira data, including bulk updates, comments, transitions, archives, deletes, sprint changes, attachments, and raw REST API calls. Use least-privilege Jira permissions, review generated JQL/manifests before execution, and require explicit confirmation for any non-GET, bulk, archive, delete, move, or --force operation.
Static analysis
No suspicious patterns detected.
