Back to skill

Security audit

Linear Autopilot

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its automation purpose, but it gives externally triggered Discord tasks broad authority to run commands, mutate Linear/Git state, and use stored credentials without enough scoping or approval controls.

Review and tighten this skill before installing: require explicit mentions or approved users for Discord triggers, reject free-form task instructions from webhooks, require confirmation before exec, Linear changes, DMs, commits, or pushes, store tokens with owner-only permissions or a secret manager, and use least-privileged Linear and Git credentials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:164
Finding

Untrusted Discord Messages Can Trigger Broad Agent Actions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:70
Finding

Linear API Key File Is Created Without Explicit Restrictive Permissions

Content
View full analysis
~/.clawdbot/linear.env ``` ``` ### Technical Analysis The setup instructions write a long-lived Linear API key to a plaintext file without explicitly setting restrictive permissions on either the containing directory or the credential file. The resulting access mode depends on the user's current `umask` and any preexisting permissions on `~/.clawdbot`. On a multi-user system with a permissive `umask`, shared home-directory permissions, inherited ACLs, or an already-accessible `.clawdbot` directory, another local account may be able to read the credential. The use of plaintext is not independently avoidable for every environment-file workflow, but the absence of explicit permission hardening creates unnecessary exposure. The example uses a placeholder rather than a hardcoded real credential, and no credential collection or exfiltration code was found. Exploitation depends on local access and insecure effective permissions. ### Attack Path 1. A user follows the documented setup instructions on a system with a permissive `umask`, inherited ACLs, or an accessible `~/.clawdbot` directory. 2. The shell creates `linear.env` with permissions that permit another local account or process to read it. 3. A local attacker enumerates the user's accessible configuration files and reads `~/.clawdbot/linear.env`. 4. The attacker extracts `LINEAR_API_KEY`. 5. The attacker uses the token against the Linear API within the permissions granted to that key. ### Impact Assessment A disclosed Linear API key could allow unauthorized access to the Linear resources available to the token owner. Depending on the token's scope and account permissions, this may include reading issue ...[truncated 314 chars]
Remediation
View remediation
"$HOME/.clawdbot/linear.env" chmod 600 "$HOME/.clawdbot/linear.env" ``` Additional hardening measures: 1. Prefer an operating-system credential store, secret manager, or runtime-injected environment variable over a persistent plaintext file. 2. Verify ownership and permissions before loading the file. Refuse to use it if it is group-readable, world-readable, or owned by another user. 3. Ensure the file is excluded from Git, backups shared with untrusted parties, diagnostic bundles, and command output. 4. Use a dedicated, least-privileged Linear token where the service supports appropriate scoping. 5. Document token rotation and revocation procedures and rotate the token immediately if file exposure is suspected. 6. Avoid passing the real token directly as a command-line argument because process listings and shell history may expose it. ]]>
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest claims risk code was removed and security improved, yet the skill still instructs shell execution, credential-based API use, external webhook automation, and automatic git push. Those capabilities are not inherently malicious, but the mismatch is dangerous because it can misrepresent operational risk and cause users or platforms to trust the skill more than warranted.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are broad terms like 'processing', 'task', and 'automate', which can cause the skill to activate in contexts far outside the intended Linear workflow. In a skill with exec and external integration capabilities, overbroad activation raises the chance of unintended command execution, state changes, notifications, or git operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The security note is misleading because the workflow explicitly has users configure API keys, Discord webhooks, bot tokens, and external automation platforms that inherently handle or transmit sensitive credentials and event data. This can lower a user's guard and encourage unsafe secret storage or over-trust in third-party integrations, increasing the risk of credential exposure or unintended data sharing.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The skill instructs users to persist a Linear API key in a plaintext file under the home directory. Persistent local secrets increase exposure to other local users, malware, backups, accidental commits, and later misuse by tools with filesystem access, especially in an automation skill that also enables exec.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

Run setup to store your Linear API key:

bash
mkdir -p ~/.clawdbot
echo "LINEAR_API_KEY=lin_api_xxxxx" > ~/.clawdbot/linear.env

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

A substantial portion of the skill description is presented in Chinese while other parts are in English, but the file does not state a language preference policy or offer users a choice. This can create a locale/language policy issue if the skill implicitly forces one language for part of the experience without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.