Back to skill

Security audit

Linear Workflow Skill Free

Security checks across malware telemetry and agentic risk

Overview

This Linear skill is mostly purpose-aligned, but its requested exec/API-key workflow is under-scoped and internally inconsistent about export, import, delete, and other higher-risk operations.

Review before installing. Use a dedicated least-privilege Linear API key, confirm every create/update/comment action before execution, and avoid relying on the undocumented export/import/delete/save/convert wording unless the publisher provides a clear CLI implementation and safeguards.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The skill claims the free edition does not support reporting/export, yet later documents export/save/convert and even delete-style operation modes as supported through generic parameters. This mismatch can cause an agent or user to invoke higher-risk operations that were not clearly scoped, increasing the chance of unintended data modification or exfiltration via exec-driven workflows.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The manifest presents a narrow Linear issue-management tool, but the body expands scope to undeclared operations like delete, import, export, save, and convert. In agent settings, this kind of scope drift is dangerous because invocation and trust decisions may be based on the manifest, while the detailed instructions steer the agent into broader, potentially destructive behaviors.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill exposes exec-driven commands and write operations like createIssue, updateIssue, and createComment without prominently warning that these actions will modify remote Linear data. In an agent environment, insufficient disclosure around remote side effects increases the risk of unintended state changes, especially when combined with broad activation language and executable tooling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.