Back to skill

Security audit

Linear Api Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This is a Linear integration guide that clearly requires user login and confirmation for write actions, with no hidden code or automatic behavior found.

Install only if you are comfortable using the Maton CLI with your Linear workspace. Confirm the target workspace, team, issue, and intended result before any create, update, delete, or comment action, and revoke the Maton or Linear connection if you stop using it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill advertises an extremely broad, keyword-driven activation scope, including generic terms like API, GraphQL, project management, and team collaboration. In an agent environment, this can cause unintended invocation and execution of read/write/exec-capable actions in contexts the user did not explicitly intend, increasing the risk of accidental data access or modification against Linear resources.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The document instructs users to authenticate, set API keys, and create OAuth connections to external services, but it does not clearly warn that credentials and project data will be transmitted to third-party services and local CLI tooling. In an agent-integrated execution context, this omission can lead users to expose sensitive tokens or organizational task data without informed consent or handling safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.