Dynamic code execution detected.
Critical
- Code
- suspicious.dynamic_code_execution
- Location
- jira_venv/lib/python3.14/site-packages/pip/_vendor/pygments/formatters/__init__.py:91
Security audit
Security checks across malware telemetry and agentic risk
The Jira logging skill has a coherent core, but it bundles real credentials, unrelated Google/Word automation, and under-scoped background service installers.
Review this package before installing. Remove bundled real credentials, avoid running the Google/Word automation unless you intentionally want those actions, and only install the LaunchAgent or background tracker if you are comfortable with a persistent local service that can create logs and send reminders.
SkillSpector could not complete.
66/66 vendors flagged this skill as clean.
Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal, suspicious.insecure_tls_verification