linear-cli

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, and the documented install sources appear publisher-consistent with verifiable releases. However, it asks the agent to install and trust a non-official third-party Linear CLI, then forward a live Linear API key to it and perform impactful external actions. Data flows appear to target official Linear services rather than an interception proxy, so this is not confirmed malware, but the supply-chain and credential-forwarding footprint is larger than ideal for a simple issue-management skill.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/oldwinter%2Fskills%2Flinear-cli%2F@300f03949ebf53e76792d53e3f13e8771f185f0c