Back to skill

Security audit

Jira集成助手-免费版

Security checks across malware telemetry and agentic risk

Overview

This appears to be a read-only Jira helper, with some disclosure and packaging gaps but no evidence of hidden, destructive, or unrelated behavior.

Before installing, treat this as a Jira Cloud read-only helper that needs your Jira email, API token, and site URL. Set JIRA_BOARD to limit searches, avoid using it with highly sensitive ticket contents unless appropriate for your organization, and be cautious with any callback_url because the artifact does not explain where callback data would go. Also verify that the referenced jira.sh scripts are actually supplied by the package or publisher, since they were not present in the inspected artifact.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill explicitly describes sending Jira data to Jira Cloud REST API and accepting an optional callback URL, but it does not clearly warn users that issue metadata and potentially sensitive project information may leave the local environment. In an agent context with exec/network capability, missing disclosure can lead users to unknowingly expose internal ticket contents, identifiers, or workflow data to external services or arbitrary callback endpoints.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.