Back to skill

Security audit

Linear 工具箱专业版

Security checks across malware telemetry and agentic risk

Overview

This Linear skill is mostly coherent, but it asks agents to perform broad bulk changes and automation in Linear without clear confirmation or scope limits.

Review this skill carefully before installing in a real Linear workspace. Use a least-privilege Linear API key, require manual confirmation before bulk edits, deletes, exports, or automation changes, and avoid enabling scheduled automation until scope and rollback behavior are clear.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition is phrased so broadly ('project management, task planning, progress tracking, team collaboration') that the skill could activate for many generic requests unrelated to Linear. In an MD+EXEC skill with read/exec/write tools and described modify/delete/automation capabilities, over-triggering increases the chance of invoking powerful actions in the wrong context or without sufficiently explicit user intent.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises create/modify/delete, export/save, and automation behaviors but does not present a prominent warning that these actions can change external state or operate in bulk. Because the skill also exposes exec/write capabilities and describes batch operations, rollback, and automation rules, a user could unintentionally authorize destructive or large-scale changes without clear informed consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.