Back to skill

Security audit

Linear 工具箱

Security checks for vulnerabilities and agentic risk

Overview

This Linear task-management skill does not show malicious behavior, but it asks for broad shell execution while supporting under-scoped Linear task changes with an API key.

Install only if you are comfortable giving the agent shell access and a Linear API key. Use a least-privileged Linear token, prefer read-only/query workflows unless you explicitly request a change, and review any command before allowing task deletion, reset/import, git push, or other state-changing actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest exposes exec, which gives the skill arbitrary shell execution capability even though the documented purpose is Linear task querying and basic task management. In an agent setting, this unnecessarily expands the attack surface because natural-language-triggered workflows could invoke local commands, filesystem operations, or chained network tooling beyond the minimum needed for the stated functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation advertises create/query/modify/delete/export/reset/import operations and ties them to execution-oriented parameters, but it does not present a consistent safety model or warning for impactful actions. In context, this is risky because the skill also has exec capability and is intended for agent-driven use, so users may not realize that natural-language requests could trigger state changes or broader local actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger condition is overly broad: 'use when project management, task planning, progress tracking, team collaboration are needed.' In an agent ecosystem, broad triggers can cause the skill to activate on ordinary conversation or adjacent requests, increasing the chance of unintended reads, task mutations, or command execution through the skill's available tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

文件标题、显示名、说明和正文均固定为中文表述,未说明是否支持其他语言,也未给用户语言/locale 选择。若组织要求技能不得在无用户同意下强制特定语言,这种默认固定语言的文案可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

At L157 the documentation says network-risk commands have been removed, creating an intent of reduced system/network command usage. However, the error-handling guidance later instructs running ping to test connectivity, which contradicts that claim rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.