linear-automation

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The artifact is an orchestration/integration guide that relies on a third-party MCP (Rube) to broker Linear API interactions. There is no direct malicious code present in the document, nor hard-coded credentials or execute-to-shell instructions. The main security concern is supply-chain and trust: centralizing OAuth tokens and arbitrary GraphQL execution with an external MCP presents significant risk for credential misuse, data exfiltration, and remote modification of workspace data if the MCP is compromised or untrusted. Recommended mitigations: vet MCP security/privacy practices, restrict OAuth scopes and token lifetimes, require human approval for destructive operations, enable audit logs and token revocation processes, or prefer direct integration with Linear where feasible.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 09:32 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Flinear-automation%2F@29a43762d752a257c52b6f62989d412ab8018239