Back to skill

Security audit

Linear项目管理

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a vague Linear/API automation wrapper that requests broad local command and file authority without enough scoping or user-control detail.

Review this carefully before installing. Only use it in an agent environment where you can restrict shell execution, file access, and API credentials, and avoid granting it broad Linear or local-system permissions until the publisher defines exact supported operations, allowed commands, file scope, and confirmation requirements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill is presented as a Linear project-management API wrapper, but it also advertises broad command execution capability. That creates unnecessary authority beyond the stated purpose and increases the risk that user input could be translated into shell actions affecting the local system. In this context, the mismatch makes accidental or unsafe execution more likely even if no explicit exploit code is shown.

Context-Inappropriate Capability

Low
Confidence
82% confidence
Finding
The skill adds general file-processing/read-write capability that is broader than a normal Linear API integration requires. Excess file access expands the attack surface by enabling unintended reads or modifications to local files unrelated to project management. The danger is moderated because the finding is about overbroad capability disclosure rather than a concrete exfiltration flow.

Vague Triggers

High
Confidence
95% confidence
Finding
The summary contains an overly broad and underspecified activation trigger, including a fragment suggesting activation when the user says a minimal token like "L". This can cause the skill to engage in contexts where the user did not intend project-management API actions, increasing the chance of unauthorized external operations or use of powerful tools without clear consent. Because the skill also declares read/exec/write tools, ambiguous invocation is especially risky.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description uses broad applicability language without clearly bounding when the skill should or should not activate. This increases the probability that the skill will be selected for loosely related tasks and then use file, network, or execution capabilities beyond user expectation. The risk is elevated by the skill's powerful tool declarations and generic automation framing.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill lacks a clear warning that it may perform write, exec, and external-system actions. Without up-front disclosure, users may invoke it expecting passive API formatting while the agent has the ability to modify local files, run commands, or affect remote systems, which undermines informed consent and safe tool use. In this skill, the absence of warning is more dangerous because the declared capabilities are materially stronger than the advertised business purpose.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.