Back to skill

Security audit

Linear项目管理工具

Security checks across malware telemetry and agentic risk

Overview

This Linear skill is not clearly malicious, but it requests broad command and file-changing authority while giving only generic Linear guidance and no clear limits on changes it may make.

Review this skill before installing. Only use it with a narrowly scoped Linear token, ask the agent to confirm before creating or modifying issues/projects, and avoid granting broad command or file-write authority unless you understand exactly what operation it will perform.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill declares access to both exec and write capabilities without clearly warning users that it can run commands and modify data. In an agent environment, hidden or under-disclosed side effects can cause users to authorize actions that alter local files or execute shell commands they did not reasonably expect.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.