Back to skill

Security audit

Linear Sync Tool Free

Security checks across malware telemetry and agentic risk

Overview

This Linear helper matches its stated purpose, but its activation scope is too broad for a tool that can read from and create records in a real Linear workspace.

Install only if you want the agent to operate against your Linear workspace. Use a least-privilege Linear API key, invoke it only for explicit Linear tasks, and confirm before allowing issue creation or commands that send task details to Linear.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill’s activation guidance is broad enough to match ordinary project-management conversations, which can cause the agent to invoke a tool with exec capability in situations where the user did not clearly request Linear operations. In this context, accidental invocation matters because the skill can query external project data and create tasks in Linear, increasing the chance of unintended external actions and data disclosure.

Vague Triggers

High
Confidence
95% confidence
Finding
The keyword coverage section is excessively expansive and effectively turns many generic project-work phrases into triggers for this skill. Because the skill exposes read, write, and exec tools and interacts with an external service, this broad trigger surface materially raises the risk of over-activation, unintended command execution, and leakage of project metadata to Linear.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill does not clearly warn that using exec with the Linear CLI can transmit project information to an external SaaS and can create remote records. Users or higher-level agents may therefore treat the skill as a local helper, underestimating the privacy and integrity impact of running commands against a real workspace.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.