T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:105- Finding
Untrusted Linear Tasks Can Trigger Broad Agent Actions and Automated Git Pushes
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill openly automates Linear tasks, but it needs Review because webhook-triggered work can update Linear and push Git changes without clear authentication, scoping, or approval safeguards.
Install only if you can tightly control who can create or move Linear issues into the monitored state, use a least-privileged Linear API key, protect or replace the plaintext env-file secret setup, disable direct auto-push unless you have a reviewed branch workflow, and require manual approval before code changes, script execution, or Git pushes.
SKILL.md:105Untrusted Linear Tasks Can Trigger Broad Agent Actions and Automated Git Pushes
SKILL.md:27Linear API Key Setup Can Expose Credentials Through Shell History and File Permissions
The skill promotes automatic processing, status changes, and Git synchronization without prominently warning that it can modify external systems autonomously. This creates a real risk of unintended issue transitions, misleading completion states, and unreviewed commits or pushes to repositories, especially when webhook-triggered.
This duplicate finding points to the same persistent plaintext secret storage pattern. The risk is not the directory creation itself, but the instruction to save an active API token in a reusable local file that may be exposed through host compromise, backups, or user mishandling.
# 创建配置目录(已gitignore)
mkdir -p ~/.linear-pilot
echo "LINEAR_API_KEY=lin_api_xxxxxxxxxxxxx" > ~/.linear-pilot/linear.env
chmod 600 ~/.linear-pilot/linear.env
This duplicate finding points to the same persistent plaintext secret storage pattern. The risk is not the directory creation itself, but the instruction to save an active API token in a reusable local file that may be exposed through host compromise, backups, or user mishandling.
# 创建配置目录(已gitignore)
mkdir -p ~/.linear-pilot
echo "LINEAR_API_KEY=lin_api_xxxxxxxxxxxxx" > ~/.linear-pilot/linear.env
chmod 600 ~/.linear-pilot/linear.env
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
mkdir -p ~/.linear-pilot echo "LINEAR_API_KEY=lin_api_xxxxxxxxxxxxx" > ~/.linear-pilot/linear.env chmod 600 ~/.linear-pilot/linear.env
获取API Key:Linear → Settings → API → Personal API keys
The documented webhook forwarding sends Linear issue data to an agent endpoint but does not warn about transmitting potentially sensitive project metadata to third-party infrastructure. Without privacy guidance, users may forward task contents, identifiers, and comments to services or endpoints that are not appropriately trusted or secured.
L211 将“研究”任务的处理方式描述为“派生子Agent调研”,但 L357 的免费版限制明确写着“❌ 子Agent任务分发”。这不是简单遗漏,而是同一文档中对该技能是否具备子Agent能力的直接自相矛盾说明。
The trigger conditions are broad enough that users may invoke the skill for loosely related integration or webhook tasks without understanding the operational consequences. In a skill that can update external task state, send notifications, and push to Git, ambiguous invocation criteria increase the chance of unintended autonomous actions against real systems.
This duplicate quick-start instruction again normalizes persistent plaintext storage of a privileged API token. In the context of an automation skill that can act on webhooks and update external systems, credential reuse from disk meaningfully increases operational security risk.
mkdir -p ~/.linear-pilot
echo "LINEAR_API_KEY=lin_api_your_key_here" > ~/.linear-pilot/linear.env
This duplicate quick-start instruction again normalizes persistent plaintext storage of a privileged API token. In the context of an automation skill that can act on webhooks and update external systems, credential reuse from disk meaningfully increases operational security risk.
mkdir -p ~/.linear-pilot
echo "LINEAR_API_KEY=lin_api_your_key_here" > ~/.linear-pilot/linear.env
The file states that the documentation and configuration examples were fully localized into Chinese to fit domestic developer habits. This indicates a language constraint in the skill materials, but there is no mention of optional language support or user opt-in for another locale.
No suspicious patterns detected.