Back to skill

Security audit

Kyaukyuai Linear Cli

Security checks for vulnerabilities and agentic risk

Overview

This Linear CLI skill is purpose-aligned but needs review because it enables write-capable authenticated Linear operations through an unpinned external CLI and under-discloses credential and mutation risks.

Review before installing. Use this only with an approved Linear workspace and least-privileged account, verify the linear CLI source and version yourself, avoid exposing auth tokens in shell history or logs, and require explicit approval for any write, webhook, raw GraphQL, or bulk operation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:72
Finding

Unpinned External CLI Dependency from a Mutable Source

Content
View full analysis
``` Related dependency metadata at lines 244–250 does not identify the required CLI as a third-party dependency: ```markdown ### 第三方依赖 | 依赖项 | 类型 | 是否必需 | 获取方式 | |:-------|:-----|:---------|:---------| | LLM API | API | 必需 | 由Agent内置LLM提供 | ### API Key 配置 - 本Skill基于Markdown指令,无需额外API Key(除内容中明确标注的外部API) ``` ### Technical Analysis The skill requires an external `linear` executable and grants the agent access to the `exec` tool, but it does not pin the CLI to a reviewed version, immutable commit, checksum, signature, or other verifiable artifact. Instead, installation is delegated to instructions hosted in a mutable personal GitHub repository. The installation URL does not itself execute code, and the audited file contains no automatic download command. However, users or agents following the prerequisite instructions may install executable code whose content can change after this skill has been reviewed. The dependency metadata compounds this issue by listing only the LLM API and omitting both the required Linear CLI and the associated Linear authentication requirement. This creates a supply-chain trust gap: subsequent commands documented by the skill treat whichever `linear` executable appears first on `PATH` as trusted. If the referenced repository, maintainer account, installation documentation, package publication channel, or release artifact is compromised, an attacker can substitute malicious executable content. ### Attack Path 1. An attacker compromises the referenced repository, its maintainer account, a release artifact, or the package channel used ...[truncated 1592 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description advertises the ability to 'read and mutate Linear' but does not prominently warn that actions can change external user or organization data. In an agent-executed environment, this omission makes the skill more dangerous because users may not realize they are granting an automated system permission to perform real, persistent operations in a production workspace.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill claims that risky code and external dependency references were removed, but the documented capability set still includes authenticated mutation of Linear data, raw GraphQL access, webhook management, config generation, and token-assisted direct API usage. This creates a misleading trust signal that may cause operators or agents to treat a high-privilege integration as safer than it really is, increasing the chance of unintended external-side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are broad and generic terms such as 'read', 'runtime', 'agent', and 'cli', which increase the chance that the skill activates in contexts unrelated to intentional Linear administration. In a skill with write-capable external integrations, overbroad activation raises the risk of accidental invocation and unintended actions against external organizational data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill explicitly instructs users to use linear auth token and send authenticated requests with curl to an external GraphQL endpoint. In context, this is expected functionality for a Linear integration, but it is still security-relevant because it enables external transmission of potentially sensitive workspace data and promotes direct use of bearer tokens in shell commands where they may be logged, exposed to history, or reused unsafely.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

linear api '{ issues(first: 5) { nodes { identifier title } } }' | jq '.data.issues.nodes[].title'

text

### Advanced: Using curl directly

For cases where you need full HTTP control, use `linear auth token`:

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The documented endpoint https://api.linear.app/graphql confirms that the skill communicates with an external service and can transmit authenticated data outside the local environment. This is not inherently malicious for a Linear skill, but it is still a true security concern because the skill has exec capability and supports direct authenticated network operations against external organizational systems.

Content

Scanner excerpt · SKILL.md (reported line 232)May include surrounding context.

For cases where you need full HTTP control, use linear auth token:

bash
curl -s -X POST https://api.linear.app/graphql \
  -H "Content-Type: application/json" \
  -H "Authorization: $(linear auth token)" \
  -d '{"query": "{ viewer { id } }"}'

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The dependency/API-key section says no additional API key is needed, yet the skill clearly depends on authenticated Linear access and even documents retrieval of an auth token for direct API use. This inconsistency can mislead users and agent wrappers about credential requirements and sensitivity, causing insecure execution assumptions around token-bearing operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file includes substantial Chinese-language descriptive and operational content in the manifest section, while the rest of the document is in English, and it does not state that the user can choose their preferred language. This can amount to an implicit language policy decision without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.