T09 · Insecure Skill Coding Practices
- Location
SKILL.md:37- Finding
Authentication Token Exposed Through CLI Output
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a legitimate Linear CLI helper, but it asks agents to handle live workspace writes and API credentials with unclear safety boundaries.
Install only if you are comfortable giving the agent command-line access to a live Linear workspace. Avoid running linear auth token, keep .linear.toml out of version control, use read-only commands first, and require explicit confirmation before creating issues, changing statuses, adding labels, comments, or using raw GraphQL.
SKILL.md:37Authentication Token Exposed Through CLI Output
SKILL.md:66Predictable Shared Temporary File Used for Issue Description
SKILL.md:223Predictable Shared Temporary File Used for Task Content
The skill recommends a safety workflow that depends on --dry-run, while later stating the free version does not support dry-run. That contradiction can lead agents to skip preflight validation and execute live write operations directly against Linear, increasing the chance of unintended remote modifications.
Manifest描述将技能范围限定为任务查询、创建、更新和团队管理,但文档后续明确列出了 project、cycle、milestone、document、user、schema、api 等命令能力,超出所声明的核心范围。尤其 linear api 允许发起原生GraphQL请求,意味着技能可操作的对象与接口面远大于描述中的基础工作流。
The skill explicitly documents token display and local credential storage without prominent warnings about secret exposure. In an agent setting, encouraging linear auth token can leak API credentials into logs, chat transcripts, shell history, or tool outputs, enabling unauthorized access to the user's Linear workspace.
The activation scope is overly broad and uses generic project-management phrases, making accidental invocation more likely in ordinary planning conversations. In an exec-enabled skill with remote write capabilities, over-triggering can cause unintended queries, issue creation, or updates in a live Linear workspace.
FAQ 明确表示可以通过 linear api 发起原生GraphQL请求,作为CLI未覆盖场景的兜底方案;而免费版限制又写明“❌ 高级GraphQL查询模板”。虽然“原生GraphQL请求”与“模板库”并非完全同义,但对用户意图层面呈现的是一边宣称受限、一边开放更强底层能力,容易造成能力边界误导。
The file states '完全中文化文档与示例' as part of the skill design, and the overall documentation is presented only in Chinese without any opt-in language selection. This can violate language/locale policy when a skill forces a specific language absent user choice or a clearly justified regional limitation.
文档在免费版限制中声称不支持 dry-run 预览和高级GraphQL查询模板,但前文推荐流程直接包含 linear issue create --dry-run --json ...,FAQ 也明确推荐使用 linear api 作为兜底能力。这会让技能表面上声称受限,但实际使用指引仍覆盖了受限/高级能力,形成描述与行为范围的不一致。
The skill includes state-changing commands such as issue creation and updates without a clear warning that these modify remote production data. In an agent context, lack of an explicit write-operation warning increases the risk of accidental record creation, status corruption, and unintended workflow changes.
No suspicious patterns detected.