Back to skill

Security audit

Linear同步(免费版)

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Linear CLI helper for viewing and creating work items, with some scoping/documentation issues but no evidence of hidden or malicious behavior.

Install only if you intend to let the agent use your authenticated Linear CLI. Keep the Linear API key least-privileged, avoid storing secrets in .linear.toml, and require confirmation before creating issues or running commands that affect your workspace.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description uses very broad natural-language triggers around project management, planning, tracking, and collaboration, which can cause the agent to invoke this exec-capable skill in loosely related contexts. In a skill that permits command execution and interacts with authenticated external systems, overbroad triggering increases the risk of unintended actions, unnecessary data access, or accidental issue creation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The capability coverage section enumerates an excessively broad keyword list, effectively expanding trigger scope far beyond precise Linear operations. Because the skill has exec access and can act against a live project-management workspace, vague keyword-based activation raises the chance of misrouting unrelated user requests into authenticated command execution and exposing workspace metadata.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

清单摘要将能力概括为“任务列表、查看与基础创建”,但正文又明确支持团队查询和项目查询,实际操作范围已超出最初的精简描述。虽然这些能力仍与Linear管理相关,但属于 manifest 顶层描述未充分声明的行为扩展。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

已知限制中明确写明免费版“不支持 Git集成”,但配置文件和环境变量示例却公开暴露了 vcs / LINEAR_VCS 配置项,值包括 git。这会让使用者合理理解为该免费版技能可配置并使用版本控制集成,与前述功能边界不一致。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
62% confidence
Finding

这里的安全说明强调不要在配置文件中明文写入 API Key,但同一文档前面广泛引导通过本地配置文件和环境变量驱动 CLI,并未在相关示例处反复区分哪些配置可落盘、哪些绝不可落盘。虽非代码执行矛盾,但属于文档层面对安全意图表达不一致,容易误导实际使用。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.