Back to skill

Security audit

Linear Api Toolkit Free

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Linear integration, but it asks users to install and authenticate a persistent third-party CLI with broad write-capable guidance that is not tightly scoped.

Review this before installing. Only use it if you trust the Maton CLI and are comfortable granting it access to your Linear workspace. Prefer a pinned, verified CLI version, avoid admin installs, restrict Linear OAuth scopes where possible, and require explicit confirmation before creating, updating, commenting on, or deleting any Linear data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:101
Finding

Unpinned Third-Party CLI Installed Globally from Mutable Package Sources

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 101-104; dependency reiterated at line 251
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: Medium

Vulnerable code:

bash
npm install -g @maton/cli
brew install maton-ai/cli/maton

The dependency table also directs users to install the same unpinned package:

markdown
| Maton CLI | CLI tool | Required | `npm install -g @maton/cli` |

Technical Analysis

The Skill instructs the Agent or user to install the latest available version of a third-party CLI globally without specifying an audited version, lockfile, package integrity hash, or trusted release signature. The project contains only SKILL.md; therefore, the behavior of the required CLI cannot be reviewed as part of this audit.

An npm installation can execute package lifecycle scripts during installation. A Homebrew installation from an external tap similarly delegates installation behavior to remotely maintained formulae and artifacts. Because no version is pinned, the effective executable and installation logic can change after this Skill has been reviewed.

This creates a supply-chain trust boundary in which compromise of the package publisher, package registry account, Homebrew tap, release artifact, or a future dependency version could introduce attacker-controlled code. Global installation also makes the resulting executable broadly available to subsequent shell and Agent operations.

Attack Path

  1. An attacker compromises the npm publisher, Homebrew tap, release infrastructure, or an upstream dependency used by the Maton CLI.
  2. The attacker publishes a malicious release under the same package or tap referenced by the Skill.
  3. An Agent or user follows the documented setup instructions without a pinned version or integrity verification.
  4. The package manager resolves the mutable latest release and downloads the compromised pa ...[truncated 1368 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the Maton CLI to a specifically reviewed version instead of installing the mutable latest release.
  2. Provide and verify official cryptographic checksums or signed release metadata before installation.
  3. For npm, use a project-local dependency with an exact version and committed lockfile rather than a global installation.
  4. Review package lifecycle scripts and consider disabling them during installation where functionality permits.
  5. For Homebrew, pin an audited formula revision and document the official tap ownership and artifact verification process.
  6. Execute the CLI in a least-privileged sandbox or container with access limited to the files, network destinations, and credentials required for the current Linear operation.
  7. Avoid installing or running the CLI with administrative privileges.
  8. Supply API credentials only at execution time, restrict OAuth scopes to required Linear operations, and rotate credentials if dependency compromise is suspected.
  9. Add dependency provenance, release-signature validation, and periodic vulnerability monitoring to the Skill's documented installation workflow.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill name, summary, and nearly all user-facing instructions are presented in Chinese, while the file also references broad compatibility with multiple AI agent platforms. There is no indication that the user can choose another language or that the Chinese-only presentation is a justified locale-specific requirement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and descriptive sections are inconsistent about whether the free edition can create comments or only view them. Capability mismatches in a skill that has write/exec permissions can cause an agent or user to invoke modifying actions they did not expect, increasing the risk of unintended data changes in Linear.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is positioned for broad project-management and team-collaboration use without tight activation boundaries. Overly broad trigger language can cause an agent to invoke this skill in routine contexts where write actions are unnecessary, exposing external systems to unintended reads or modifications.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

One section says the free version excludes bulk operations, while another describes create/update/export modes in generic terms that can be read as enabling broader operational coverage. Contradictory capability descriptions can cause overbroad agent behavior, including higher-volume write activity than the user expects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation states that input modes support delete operations even though the rest of the free-version description says advanced or restricted write capabilities are limited. Mentioning deletion without a consistent policy or guardrail is dangerous because an agent may infer destructive operations are permitted and attempt them against live project data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes modification and deletion-style operations without an upfront warning that it may alter user data in an external system. In a tool with write and exec access, lack of a prominent mutation warning raises the chance of accidental destructive or irreversible actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The keyword coverage section includes expansive, generic phrases that map to many normal work conversations. In an agent routing context, such broad keywords increase accidental activation and may route unrelated tasks into a skill with write and exec capabilities.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.