Back to skill

Security audit

Linear项目管理工具

Security checks across malware telemetry and agentic risk

Overview

This is a mostly plain Markdown Linear helper, but it asks for broader local command and file-write authority than its Linear purpose clearly needs.

Review this before installing if you only need Linear issue lookup. If installed, use it only for explicit Linear tasks, avoid giving it broad project or credential access, and require confirmation before creating or changing Linear issues, writing local files, or running commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
79% confidence
Finding
The invocation description is so broad that an agent may select this skill for loosely related requests, increasing the chance of unintended execution in contexts involving project data, file operations, or external integrations. Because the skill also advertises exec/write/API capabilities elsewhere, ambiguous triggering raises the risk of accidental side effects or overbroad authority use.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill claims file writing, API integration, and command execution capabilities without prominent guardrails, consent requirements, or impact warnings. In an agent environment, this can lead to unauthorized local changes, unsafe command execution, or unintended transmission of sensitive data to external services if the skill is invoked too broadly or with attacker-influenced inputs.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.