Back to skill

Security audit

Linear项目管理工具

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a generic Linear helper, but it asks for broad read/write/execute and API capabilities without enough clear, Linear-specific boundaries.

Install only if you are comfortable manually supervising each Linear action and any file, command, or API use. Use a least-privilege Linear token, avoid broad workspace credentials, and require explicit confirmation before creating, updating, assigning, or bulk-changing issues or projects.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The documented output schema is unrelated to the stated Linear functionality and instead shows a generic grading report. This kind of semantic mismatch can mislead an agent or user into trusting incorrect downstream behavior, causing improper automation decisions, unsafe parsing assumptions, or accidental misuse of the skill in workflows that expect Linear project data.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill declares Linear-specific inputs such as team_id and status, but the output contract describes unrelated code-quality scoring data. This inconsistency can cause agents to invoke the skill under false assumptions, route data incorrectly, or accept fabricated results as legitimate Linear output, undermining integrity of automated project-management workflows.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill advertises file handling, API integration, and command execution capabilities but does not clearly warn users when these impactful operations may occur or what boundaries apply. In an agent environment, this increases the risk of unexpected external actions, data modification, or command execution being triggered under vague natural-language instructions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.