Back to skill

Security audit

Linear Workflow Skill Free

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Linear management purpose is legitimate, but it asks users to install and run an unbundled Node CLI that would handle API credentials and mutate Linear data.

Install only if you are comfortable reviewing or supplying the missing CLI yourself. Use a dedicated least-privilege Linear API key, confirm every write action before execution, and avoid running npm install from unreviewed files or directories.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:102
Finding

Unverifiable and Unpinned Node.js Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:102
Vulnerability Type: Uncontrolled third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
cd {baseDir}/scripts && npm install

A related dependency declaration appears at SKILL.md:257:

text
| @linear/sdk | Node package | Required | npm install |

Technical Analysis

The skill instructs users or agents to run npm install in a scripts directory, but the reviewed project contains only SKILL.md. It does not contain the referenced directory, a package.json, a lockfile, the advertised CLI implementation, pinned dependency versions, or package integrity metadata.

Consequently, the dependency graph and any npm lifecycle scripts cannot be reviewed or reproduced. The command fails in the artifact as audited because the referenced directory is absent. However, if that directory is later supplied from an unreviewed source or created by another process, following the documented installation procedure could install uncontrolled package versions and execute lifecycle hooks such as preinstall, install, or postinstall.

This finding does not establish that @linear/sdk is malicious. The risk arises from directing installation without shipping a verifiable manifest, exact versions, integrity-protected lockfile, and auditable implementation.

Attack Path

  1. A user or agent trusts the installation instructions in SKILL.md.
  2. A missing scripts directory is later obtained from an unreviewed source or populated by a process with write access to the project.
  3. That directory contains a manipulated package manifest, malicious dependency, or npm lifecycle hook.
  4. The user or agent runs the documented npm install command.
  5. npm resolves the uncontrolled dependencies and may execute lifecycle scripts under the invoking user's account.
  6. Malicious installation code can act with the filesystem, net ...[truncated 652 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the complete claimed CLI implementation and its scripts directory in the reviewed package.
  2. Supply a valid package.json and an integrity-protected lockfile such as package-lock.json.
  3. Pin dependencies to reviewed versions rather than relying on unconstrained resolution.
  4. Use npm ci for deterministic installation instead of npm install.
  5. Use npm ci --ignore-scripts when lifecycle scripts are unnecessary.
  6. If lifecycle scripts are required, document and audit each script before installation.
  7. Verify dependency provenance and package integrity in CI.
  8. Fail closed when the expected manifest, lockfile, or CLI files are absent rather than directing users to obtain unspecified external content.
  9. Run dependency installation in an isolated, minimally privileged environment without production credentials.

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:27
Finding

Excessive Filesystem and Command-Execution Tool Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:27
Vulnerability Type: Violation of least-privilege tool access
Risk Level: Low

Vulnerable Code

yaml
tools: ["read", "write", "exec"]

Technical Analysis

The skill requests general-purpose read, write, and command-execution capabilities. Its stated purpose is to interact with Linear through a Node.js CLI, but the documented workflow does not establish a need for unrestricted filesystem write access. Generic exec also provides a substantially broader capability than a narrowly scoped Linear API operation.

Broad tool grants increase the consequences of malformed user input, unsafe command construction, misleading external data, or future changes to the skill instructions. Although the reviewed file does not explicitly instruct the agent to abuse these permissions, granting capabilities beyond the legitimate task violates least privilege.

The frontmatter also contains duplicate tools declarations. Different YAML parsers may resolve duplicate keys differently, making the effective permission declaration ambiguous.

Attack Path

  1. The skill is loaded with general write and exec capabilities.
  2. A user request, untrusted issue content, or future skill instruction induces an unsafe operation.
  3. The agent uses generic command execution or filesystem writing instead of a constrained Linear operation.
  4. Commands execute and files are modified with the permissions of the agent process.

This is an enabling condition rather than evidence of an embedded malicious payload. Exploitation requires a separate instruction-manipulation, unsafe-input, or command-construction condition.

Impact Assessment

If misused, write could modify any files accessible to the agent process, while exec could run arbitrary local commands with that process's operating-system privileges. Potential scope includes the current project, user-writable configurati ...[truncated 228 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the generic write permission unless a documented workflow strictly requires local file creation or modification.
  2. Replace unrestricted exec with a dedicated Linear integration exposing only approved operations.
  3. If command execution is unavoidable, allowlist the bundled CLI executable and supported subcommands.
  4. Pass arguments through structured process APIs rather than shell-string concatenation.
  5. Validate issue identifiers, team identifiers, status identifiers, and JSON arguments before execution.
  6. Run the CLI in a sandbox with restricted filesystem and network access.
  7. Exclude unrelated environment variables and secrets from the CLI process.
  8. Consolidate the duplicate tools declarations into one unambiguous least-privilege declaration.
  9. Require explicit user confirmation before performing state-changing Linear operations.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes exec-based commands and write-capable issue/comment updates early in the document, but it does not provide a prominent upfront warning that using the skill can directly modify remote Linear data. In an agent environment, insufficiently explicit mutation warnings can lead to accidental state changes, especially when commands are executed on the user's behalf.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation scope is defined with a very broad set of generic workflow and project-management keywords, increasing the chance that the skill is auto-selected for loosely related requests. Because the skill has write and exec capabilities, over-broad triggering can cause unintended issue creation, updates, or comments in Linear when a user did not explicitly request those actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The display name and most instructional text are in Chinese, with no statement that users may choose another language or locale. Because this is user-facing natural-language guidance for a general-purpose skill, the absence of an explicit language option can conflict with a policy requiring language/locale choice or opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest and surrounding documentation consistently describe the skill as supporting issue/project querying, creation, updates, and comments. However, the technical summary says it supports '创建/查询/修改/删除' modes, which contradicts the declared feature set and exposed commands.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The free-version limitations explicitly state that bulk operations are unavailable, yet the scenarios describe creating multiple issues and using batch queries as part of normal use. This is an intent/documentation contradiction within the skill file rather than a mere omission.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.