Back to skill

Security audit

Linear

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Linear MCP integration that stores Linear OAuth credentials locally and lets the agent read or modify Linear data with confirmation for writes.

Install only for a Linear account and workspace you intend the agent to access. Treat it as operating with that account's Linear permissions, confirm any creates, updates, or deletes carefully, avoid sending unrelated secrets or personal data through Linear tool calls, and revoke the OAuth grant in Linear when no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says this skill is a thin pass-through to Linear's hosted MCP server for reading and writing Linear workspace data. The provided code does not interact with Linear APIs, Linear workspace objects, or an MCP tool catalog. Instead, it initializes OAuth state for an MCP server by extracting credentials from environment variables and storing them in mcporter's vault. That is a materially different primary purpose and an undeclared capability involving credential handling and vault writes. While this could be supporting infrastructure for MCP access, the supplied chunk itself is not a Linear data access pass-through and is server-agnostic, so the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
- `MAVERICK_LINEAR_MCP_EXPIRES_IN`
- `MAVERICK_LINEAR_MCP_REFRESH_TOKEN_EXPIRES_AT`

These expiry fields are vault metadata, not tool arguments. They let mcporter make better pre-request refresh decisions for the access token and preserve refresh-token expiry information when the upstream OAuth response includes it.

**Setup-time prerequisites.** Setup needs `bash`, `jq`, and `mcporter` (>= v0.11.0) on `PATH`. These are gated by the install caller, not by `requires.bins` in this file, which gates agent-runtime eligibility. If setup fails, verify those binaries are present and current before retrying.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation text says to use the skill whenever the user asks about Linear work or wants to read or write Linear data, which is broad enough to encourage automatic invocation in ambiguous cases. Because the skill can perform writes and delete operations through a remote MCP server, overly eager activation increases the chance of unnecessary data exposure to Linear or unintended state-changing actions.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The instruction to call any tool from the live catalog delegates capability boundaries to whatever the remote Linear MCP server advertises at runtime. That creates a broad authority surface: if the catalog changes, includes destructive tools, or publishes risky instructions, the agent may invoke capabilities not reviewed in this skill, leading to unintended writes, deletions, or transmission of sensitive workspace content to the provider.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

The output includes Linear's Instructions: field (read it - it specifies, for example, how to format markdown content) and a JSON Schema for every tool's parameters. Treat this as the authoritative reference for the rest of the session.

Step 2 - Call any tool from the catalog using the form <server>.<tool> where <server> is maverick-linear (the local registration key, not the published skill name):

sh
mcporter --config {baseDir}/mcporter.json call maverick-linear.<tool> <arg>=<value> ...

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · mcporter.json (reported line 9)May include surrounding context.

json
"transport": "http",
      "auth": "refreshable_bearer",
      "refresh": {
        "tokenEndpoint": "https://api.linear.app/oauth/token",
        "clientIdEnv": "MAVERICK_LINEAR_MCP_CLIENT_ID",
        "clientSecretEnv": "MAVERICK_LINEAR_MCP_CLIENT_SECRET",
        "clientAuthMethod": "client_secret_basic"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code reads sensitive credentials from environment variables and pipes them into mcporter vault set, which writes them into a vault entry. Although comments explain implementation details, there is no user-facing prompt, warning, or runtime disclosure before handling and storing these secrets.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/init-mcporter-oauth.sh:77