daily-update
Warn
Audited by Socket on May 5, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the drafting behavior is narrowly scoped and mostly coherent, but the skill's trust boundary depends on a non-official third-party Linear CLI that may hold/use a real Linear API key, and it can trigger transitive skill installation. No clear malicious exfiltration is shown, but the install/credential trust model is disproportionate enough to warrant caution.
Confidence: 89%Severity: 74%
Audit Metadata