Back to skill

Security audit

Linear Flow Cli Free

Security checks for vulnerabilities and agentic risk

Overview

This skill is a legitimate Linear CLI helper, but it asks agents to handle live workspace writes and API credentials with unclear safety boundaries.

Install only if you are comfortable giving the agent command-line access to a live Linear workspace. Avoid running linear auth token, keep .linear.toml out of version control, use read-only commands first, and require explicit confirmation before creating issues, changing statuses, adding labels, comments, or using raw GraphQL.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:37
Finding

Authentication Token Exposed Through CLI Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:66
Finding

Predictable Shared Temporary File Used for Issue Description

Content
View full analysis
/tmp/description.md <<'EOF' ... EOF linear issue create \ --title "..." \ --description-file /tmp/description.md \ --team ENG \ --priority 2 ``` ### Technical Analysis The documented workflow writes Issue content to the fixed path `/tmp/description.md`. On multi-user Unix-like systems, `/tmp` is normally shared and writable by all local users. A predictable filename can collide with another process's file or be pre-created as a symbolic link. Shell redirection follows symbolic links. Consequently, if the Agent's account can write to the link target, the redirection may overwrite an unintended file. An attacker may also replace or modify the temporary content before the subsequent `linear issue create` command reads it, resulting in attacker-controlled content being sent to Linear. The exposure is constrained by local filesystem permissions and requires an attacker or untrusted process capable of manipulating the shared temporary path. ### Attack Path 1. An attacker predicts that the Skill will use `/tmp/description.md`. 2. Before execution, the attacker creates that path as a symbolic link to another file, or repeatedly replaces the path during the interval between creation and use. 3. The Agent executes the documented redirection. 4. The shell follows the symbolic link and overwrites a file writable by the Agent, or the attacker replaces the resulting description content. 5. The Agent submits the modified file to Linear through `--description-file`. 6. The unintended content is published in the created Issue, or an unintended local file is modified. ### Impact Assessment Potential impact includes modification of files writable by the Agent account, corruption or substitution of an Issue description, and disclosure of file content if an attacker can cause the CL ...[truncated 291 chars]
Remediation
View remediation
"$description_file" <<'EOF' Issue description EOF linear issue create \ --title "Issue title" \ --description-file "$description_file" \ --team ENG \ --priority 2 ``` ]]>

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:223
Finding

Predictable Shared Temporary File Used for Task Content

Content
View full analysis
/tmp/task.md linear issue create --title "..." --description-file /tmp/task.md --team ENG ``` ### Technical Analysis The example writes task content to the fixed filename `/tmp/task.md` and subsequently passes that file to the Linear CLI. Because the path is predictable and located in a shared temporary directory, another local process can pre-create the path, redirect it through a symbolic link, or alter the file between the write and read operations. The separate write and use commands also introduce a time-of-check/time-of-use window. Even when the initial write creates a regular file, another process with sufficient local access may replace it before `linear issue create` reads it. ### Attack Path 1. An attacker observes or predicts use of `/tmp/task.md`. 2. The attacker creates a symbolic link at that path or monitors it for creation. 3. The Agent executes the redirection to `/tmp/task.md`. 4. The write affects the symbolic-link target, or the attacker replaces the generated file after it is written. 5. The Linear CLI reads the attacker-controlled or unintended file. 6. Manipulated task content is submitted to Linear, or a local file writable by the Agent is overwritten. ### Impact Assessment An attacker may alter the description of the created Linear Issue or cause modification of another file writable by the Agent account. Under favorable race conditions, unintended local file content could also be consumed as an Issue description. The issue does not grant permissions beyond those of the executing account. Practical exploitation requires another local user or untrusted process with access to the shared temporary directory. ]]>
Remediation
View remediation
"$task_file" linear issue create \ --title "Task title" \ --description-file "$task_file" \ --team ENG ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill recommends a safety workflow that depends on --dry-run, while later stating the free version does not support dry-run. That contradiction can lead agents to skip preflight validation and execute live write operations directly against Linear, increasing the chance of unintended remote modifications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Manifest描述将技能范围限定为任务查询、创建、更新和团队管理,但文档后续明确列出了 project、cycle、milestone、document、user、schema、api 等命令能力,超出所声明的核心范围。尤其 linear api 允许发起原生GraphQL请求,意味着技能可操作的对象与接口面远大于描述中的基础工作流。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly documents token display and local credential storage without prominent warnings about secret exposure. In an agent setting, encouraging linear auth token can leak API credentials into logs, chat transcripts, shell history, or tool outputs, enabling unauthorized access to the user's Linear workspace.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation scope is overly broad and uses generic project-management phrases, making accidental invocation more likely in ordinary planning conversations. In an exec-enabled skill with remote write capabilities, over-triggering can cause unintended queries, issue creation, or updates in a live Linear workspace.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

FAQ 明确表示可以通过 linear api 发起原生GraphQL请求,作为CLI未覆盖场景的兜底方案;而免费版限制又写明“❌ 高级GraphQL查询模板”。虽然“原生GraphQL请求”与“模板库”并非完全同义,但对用户意图层面呈现的是一边宣称受限、一边开放更强底层能力,容易造成能力边界误导。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file states '完全中文化文档与示例' as part of the skill design, and the overall documentation is presented only in Chinese without any opt-in language selection. This can violate language/locale policy when a skill forces a specific language absent user choice or a clearly justified regional limitation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

文档在免费版限制中声称不支持 dry-run 预览和高级GraphQL查询模板,但前文推荐流程直接包含 linear issue create --dry-run --json ...,FAQ 也明确推荐使用 linear api 作为兜底能力。这会让技能表面上声称受限,但实际使用指引仍覆盖了受限/高级能力,形成描述与行为范围的不一致。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill includes state-changing commands such as issue creation and updates without a clear warning that these modify remote production data. In an agent context, lack of an explicit write-operation warning increases the risk of accidental record creation, status corruption, and unintended workflow changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.