Linear

Security checks across malware telemetry and agentic risk

Overview

This Linear integration is coherent and disclosed, but users should be careful because it can modify or delete Linear data through an authenticated Membrane connection.

Install only if you want your agent to manage Linear through Membrane. Use the least-privileged Linear account practical, review Membrane CLI trust before global npm installation, and require explicit confirmation before deletes, bulk updates, or raw proxy API requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents a destructive action, `delete-issue`, without any warning, confirmation requirement, or guidance to verify user intent. In an agentic setting, this increases the risk of accidental or premature destructive operations against production project data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal