Back to skill

Security audit

Linear项目管理工具

Security checks for vulnerabilities and agentic risk

Overview

This Linear skill appears non-malicious, but it asks for broad local read, command execution, and write authority without enough scoping or user-control guidance.

Review this skill before installing. Use it only if you are comfortable giving the agent broad local tool access while working with Linear data, and require explicit confirmation before it creates or modifies issues, projects, assignments, or local files.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:25
Finding

Excessive Agent Tool Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25–28
Vulnerability Type: Excessive tool permissions and violation of least privilege
Risk Level: Medium

yaml
tools:
- read
- exec
- write

Technical Analysis

The skill requests read, exec, and write capabilities, although its documented purpose is to manage Linear issues, projects, and team workflows. The file does not contain an implementation or documented workflow that requires arbitrary local command execution or filesystem modification.

Declaring exec and write unnecessarily expands the skill's authority. If these permissions are granted by the hosting agent, untrusted task content or instruction injection could potentially induce the agent to execute local commands or alter files. The risk arises from excessive capability exposure rather than from an explicitly malicious command in the audited file.

Attack Path

  1. The agent loads the skill and grants the tools declared in its metadata.
  2. The skill receives attacker-controlled task content, issue content, or other untrusted instructions.
  3. Malicious content persuades or instructs the agent to invoke exec or write.
  4. The agent executes a local command or modifies a file under its operating-system identity.
  5. The resulting access is limited only by the permissions and sandbox controls applied to the agent process.

Impact Assessment

Successful exploitation could permit command execution and filesystem modification with the privileges of the agent process. Depending on the runtime environment, this could affect project files, accessible user files, local configuration, or credentials readable by that process.

No direct malicious command, persistence mechanism, remote payload retrieval, credential theft, or data-exfiltration behavior was found in the audited file. Exploitation therefore depends on the agent granting the declared capabilities and subsequentl ...[truncated 48 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec and write from the declared tool list unless a specific, documented operation requires them.
  2. Use a narrowly scoped Linear API integration rather than general-purpose shell or filesystem capabilities.
  3. Grant read-only Linear permissions by default and require explicit user confirmation before creating or modifying issues, projects, or workflow state.
  4. If local execution is unavoidable, restrict commands through an allowlist, isolate execution in a sandbox, and deny access to credentials and unrelated files.
  5. Treat issue descriptions, project content, and other externally sourced text as untrusted data rather than executable instructions.
  6. Log sensitive tool invocations and clearly present the intended command or file modification to the user before execution.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is overly broad, mixing generic automation, project management, and unspecified capabilities without clearly bounding what actions the agent may take. In a skill that also advertises read/exec/write tools, this ambiguity can cause an agent or user to invoke it in contexts that unintentionally expose data or trigger unsafe actions beyond the expected Linear workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown declares read, exec, and write capabilities, but does not clearly warn that using the skill may modify external project data or execute commands in the local environment. Because the skill is framed as a general Linear management tool, a user may reasonably expect informational queries while the agent still has authority to perform mutations or command execution, increasing the risk of accidental data changes or unsafe side effects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.