Back to skill

Security audit

Linear工作流机器人

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Linear automation helper, but it gives an agent broad automatic execution and Git push authority from external task inputs without enough scoping or review controls.

Install only if you are prepared to review and constrain its automation. Disable automatic Git pushes by default, run on a limited branch and repository credential, authenticate webhook events, allowlist trusted Linear users or labels, keep bot-triggered events disabled unless necessary, and require a human diff review before commits or pushes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:21
Finding

Untrusted External Tasks Can Trigger Privileged Agent Actions and Automatic Repository Pushes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21–24, 37, 92–93, 120–123, 136, and 161
Vulnerability Type: Untrusted task execution with excessive Agent and repository authority
Risk Level: High

Vulnerable Code Snippets

yaml
tools:
- read
- exec
- write
markdown
Automatic pipeline: **Linear → Webhook platform → Notification channel → Task execution → Git synchronization**. Tasks created in Linear automatically trigger processing, real-time notification, execution, result write-back, and synchronization to a Git repository.
json
{
  "notify": {
    "channel": "discord",
    "discord": {
      "botToken": "${DISCORD_BOT_TOKEN}",
      "notifyUserId": "discord-user-id",
      "taskChannelId": "channel-id",
      "allowBots": true
    }
  },
  "git": {
    "repo": "/path/to/repo",
    "autoPush": true,
    "commitPrefix": "task:",
    "branch": "main",
    "conflictStrategy": "rebase"
  }
}
markdown
| 4. Execute task | Invoke a sub-Agent or local script | Mark as "Stalled" after a 30-minute timeout |
| 7. Git synchronization | git add/commit/push | Handle conflicts according to conflictStrategy |
bash
git add research/ && commit -m "task: ENG-456 wasm research" && push
markdown
**Availability classification:** MD+EXEC (Markdown instructions requiring exec to run scripts and webhook calls).

Technical Analysis

The Skill defines an automation boundary in which task data originates from Linear and passes through externally managed webhook and notification services before being delegated to a sub-Agent or local script. The receiving Agent is granted read, write, and exec capabilities, while the Git configuration enables automatic pushes.

The documentation does not define controls that distinguish trusted workflow metadata from untrusted task content. In particular, it does not specify:

  • Authentication and signature verification for incoming webhook events.
  • Authorization rules fo ...[truncated 3195 chars]
Remediation
View remediation

Remediation Suggestions

  1. Authenticate incoming events

    • Require webhook signature or HMAC verification.
    • Validate timestamps and unique delivery identifiers to prevent replay attacks.
    • Reject events from unknown teams, projects, integrations, and webhook endpoints.
  2. Authorize task initiators

    • Maintain an explicit allowlist of Linear users and service identities permitted to initiate automation.
    • Require project or label-based authorization in addition to watchFilter.
    • Do not treat possession of task-editing access as authorization to execute local operations.
  3. Treat task content strictly as untrusted data

    • Parse incoming events into a typed schema.
    • Permit only fixed action identifiers with predefined behavior.
    • Do not translate arbitrary task prose into shell commands.
    • Explicitly instruct the Agent that task titles, descriptions, comments, attachments, and bot messages cannot change system policy or request additional privileges.
  4. Constrain command execution

    • Replace general-purpose exec with narrowly scoped wrapper functions.
    • Use an exact executable and argument allowlist; avoid shell interpretation.
    • Run tasks in an isolated container or sandbox with no unnecessary host mounts.
    • Disable access to unrelated environment variables, credentials, SSH agents, and network destinations.
  5. Restrict filesystem authority

    • Resolve and canonicalize the configured repository path.
    • Reject path traversal, symbolic-link escapes, absolute output paths, and writes outside the approved workspace.
    • Grant read access only where necessary and write access only to designated output directories.
  6. Harden Git synchronization

    • Set autoPush to false by default.
    • Generate changes on a dedicated, non-protected branch using least-privilege credentials.
    • Require human approval after reviewing the command plan and complete diff.
    • Protect default branches and re ...[truncated 1012 chars]
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
tools:
- read
- exec
- write
homepage: '""'
category: '"Automation"'
pricing_tier: free

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill performs state-changing actions including task execution, status transitions, file generation, Git commit, and Git push, but it does not present a clear upfront warning that these operations modify local and remote systems. In an agent setting, missing prominent disclosure and confirmation increases the risk of unintended side effects, repository changes, or propagation of attacker-influenced content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares conflicting availability models: one section says exec is required for scripts and webhook calls, while another says it is pure Markdown driven by natural language. This can mislead the agent or user about whether code execution is expected, weakening safety controls and increasing the chance that risky actions are performed without the right execution gating or review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill claims it does not concatenate user input into command parameters, but the documented workflow uses task-derived values such as issue IDs, summaries, filenames, commit messages, and comments in shell commands and API calls. If those values are attacker-controlled or insufficiently validated, this can lead to command injection, argument injection, unsafe Git operations, or malicious content being pushed to external systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The display name and primary descriptive content are written in Chinese, and the document does not indicate that other languages are supported or that the language is region-specific by design. This can violate a language/locale policy when users are not given a choice or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.