Back to skill

Security audit

Linear CLI专家

Security checks for vulnerabilities and agentic risk

Overview

This Linear CLI skill is mostly purpose-aligned, but it includes unsafe shell templates and overbroad activation guidance that should be reviewed before use.

Install only if you need an agent to operate Linear through the CLI, and review commands before execution. Avoid the provided CSV batch template unless rewritten with a real CSV parser, safe argument passing, and mktemp-based files. Do not let the agent print tokens, reuse the curl pattern for non-Linear URLs, or run broad Linear mutations without explicit preview and confirmation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:121
Finding

Command Injection Through Unsafe CSV Interpolation

Content
View full analysis
/tmp/desc_$$.md linear issue create --title "$title" --team "$team" --description-file /tmp/desc_$$.md --json rm -f /tmp/desc_$$.md ' ``` ### Technical Analysis The template substitutes each CSV row directly into a command string interpreted by `bash -c`. Because the substituted value appears inside shell source code rather than being passed as an inert argument, a row containing quotation marks, command substitutions, newlines, or other shell metacharacters can break out of the intended here-string and introduce arbitrary shell commands. The use of `IFS=, read` is also not a valid general-purpose CSV parser. Quoted fields, embedded commas, and embedded newlines can be parsed incorrectly, further increasing the likelihood that data will alter command structure. ### Attack Path 1. An attacker supplies or modifies an `issues.csv` file that the Agent is asked to import. 2. A CSV row contains shell syntax crafted to terminate the `<<< "{}"` expression and append an attacker-selected command. 3. The Agent follows the documented batch-import template. 4. `xargs` performs textual replacement of `{}` inside the `bash -c` command string. 5. Bash parses and executes the injected syntax with the privileges of the Agent process. 6. The injected process can access any files, environment variables, credentials, and network resources available to that account. ### Impact Assessment Successful exploitation provides arbitrary command execution under the operating-system account running the Agent. The resulting scope is not limited to Linear: it can include project files, environment variables, local credentials, writable filesystem locations, and network services accessible to the Agen ...[truncated 179 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:123
Finding

Predictable Temporary File Permits Symlink and Race Attacks

Content
View full analysis
/tmp/desc_$$.md linear issue create --title "$title" --team "$team" --description-file /tmp/desc_$$.md --json rm -f /tmp/desc_$$.md ``` ### Technical Analysis The temporary filename is derived only from the shell process ID and is therefore predictable. Shell redirection creates or truncates the path without requesting exclusive creation and follows symbolic links. A local attacker who can write to the shared temporary directory may pre-create the predicted path as a symbolic link. The redirection can then overwrite the linked target if the victim account has permission. There is also a time-of-check/time-of-use window between writing the file and passing it to `linear`, allowing content substitution in environments where another local principal can manipulate the path. The cleanup command operates on the same predictable pathname and is not guaranteed to execute if an earlier command fails or the process is interrupted. ### Attack Path 1. A local attacker observes or predicts the process ID used by the import shell. 2. The attacker creates `/tmp/desc_.md` as a symbolic link to a target writable by the Agent account. 3. The Agent executes the documented import template. 4. The shell follows the symbolic link while processing `echo "$desc" > /tmp/desc_.md`. 5. The linked target is truncated and overwritten with issue-description data. 6. Alternatively, the attacker replaces or modifies the temporary object before `linear` reads it, causing attacker-selected content to be uploaded to Linear. ### Impact Assessment The overwrite impact is limited to files writable by the Agent account, so this does not by itself bypass operating-system access controls. Within that boundary, it can corrupt project or configuration files, disclose or alter issue conte ...[truncated 206 chars]
Remediation
View remediation
"$tmp_file" linear issue create \ --title "$title" \ --team "$team" \ --description-file "$tmp_file" \ --json ``` - Prefer a private temporary directory created with `mktemp -d` and mode `0700` when processing multiple records. - Use `printf` rather than `echo` for predictable handling of data beginning with options or containing escape sequences. - Stream content through standard input where the CLI supports it, avoiding temporary files entirely. - Ensure cleanup occurs through a trap on normal completion, errors, and common termination signals. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:158
Finding

Linear API Key Exposed Through Process Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The batch template writes user-controlled content into predictable temporary files under /tmp and then deletes them with a shell command. In shared environments this can create symlink/race risks and accidental file clobbering or disclosure, especially because /tmp/desc_$$.md is guessable and the example encourages automated concurrent execution.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

IFS=, read -r title team desc <<< "{}" echo "$desc" > /tmp/desc_$$.md linear issue create --title "$title" --team "$team" --description-file /tmp/desc_$$.md --json rm -f /tmp/desc_$$.md '

text

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill discloses the local credential storage path ~/.config/linear/credentials.json, which meaningfully aids credential discovery in environments where the agent also has read access. In a tool-enabled agent context, naming the secret-bearing file lowers the barrier for accidental or malicious credential access and reuse.

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

md
**Q4: heredoc 在 Windows PowerShell 报错?**
A: PowerShell 不支持 heredoc。改用文件:把查询写入 `.graphql` 文件,用 `linear api --query-file query.graphql`(如 CLI 不支持该 flag,则用 `Get-Content query.graphql -Raw | linear api`).
**Q5: token 存哪里?**
A: `linear auth login` 交互式登录后存于 `~/.config/linear/credentials.json`。CI 环境用 `LINEAR_API_KEY` 环境变量,不要写入代码仓库.
## 排错指南
| 现象 | 排查路径 |
|:------|------:|

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation text is broad enough to match generic development tasks ('代码生成、编程辅助、调试测试、开发部署'), which can cause the skill to be invoked in contexts far beyond Linear management. Because the skill has exec and write capabilities, over-broad triggering increases the chance of unnecessary command execution and exposure of project metadata or credentials during unrelated tasks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill explicitly instructs sending data to an external endpoint via curl and includes use of an authorization header derived from linear auth token. In an agent setting, this creates a direct exfiltration channel for workspace data and bearer credentials if the pattern is copied to arbitrary destinations or used without strict endpoint validation.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

text

简单查询可内联:`linear api '{ viewer { id name email } }'`.
### curl 兜底(需完全 HTTP 控制时)

```bash
curl -s -X POST https://api.linear.app/graphql \

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

Referencing https://api.linear.app/graphql confirms intentional external network transmission to a third-party service. While expected for Linear usage, it is still security-relevant because the skill enables outbound data flow from the agent runtime and may carry sensitive issue contents or metadata.

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

curl 兜底(需完全 HTTP 控制时)

bash
curl -s -X POST https://api.linear.app/graphql \
  -H "Content-Type: application/json" \
  -H "Authorization: $(linear auth token)" \
  -d '{"query": "{ viewer { id } }"}'

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Lines L391-L393 describe the skill as 'MD(纯Markdown指令,通过自然语言驱动Agent完成操作)', which implies no command execution is required. However, elsewhere the document repeatedly instructs the agent to run linear, curl, git, and shell pipelines, and even earlier classifies the skill as 'MD+EXEC' at L281-L283. This is an active contradiction in the skill's own documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language description contains mixed Chinese and English phrasing and presents the skill as 'Linear CLI专家' without indicating whether users may choose their preferred language. This can violate a language/locale policy when a skill effectively imposes a language style by default rather than explicitly offering opt-in or alternatives.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

L035 says '所有 Markdown 内容走文件/stdin 而非内联', presenting a strong safety rule against inline content. Later examples explicitly allow inline query content such as linear api '{ viewer { id name email } }' at L190, which weakens and contradicts the earlier absolute guidance. While the later case is GraphQL rather than Markdown, the documentation presents the earlier rule as categorical and then violates that intent with inline content examples.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.