linear

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is narrow and plausible, but the skill depends on an unofficial personal-repo CLI installed via unpinned curl|bash, then passes a real Linear API key into that binary. That combination is disproportionate to a simple read/search integration and creates substantial supply-chain and credential-forwarding risk.

Confidence: 93%Severity: 90%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:52 AM
Package URL
pkg:socket/skills-sh/lwlee2608%2Fagent-skills%2Flinear%2F@f875668d5d44554003df256b4c80f553b4a38f47