扫描报告
5 /100
linear-cli
Use the linear-cli agent-native runtime to read and mutate Linear from Claude Code, Codex, or other agents
This is a legitimate Linear CLI wrapper skill with no malicious behavior. All capabilities are clearly documented and the script is a documentation generator for the CLI tool.
可以安装
No action needed. The skill is safe to use as documented.
安全发现 1 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 低危 | Implicit filesystem read capability 文档欺骗 | SKILL.md:50 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 命令执行 | WRITE | WRITE | ✓ 一致 | SKILL.md declares Bash(linear:*) and Bash(curl:*) for executing the Linear CLI a… |
| 文件系统 | NONE | READ | ✓ 一致 | SKILL.md shows --description-file and --body-file flags for reading local files,… |
| 网络访问 | READ | READ | ✓ 一致 | SKILL.md documents https://api.linear.app/graphql as the Linear API endpoint |
1 项发现
中危 外部 URL 外部 URL
https://api.linear.app/graphql SKILL.md:207 目录结构
27 文件 · 150.1 KB · 4120 行 Markdown 26f · 3765L
TypeScript 1f · 355L
├─
▾
references
│ ├─
api.md
Markdown
│ ├─
auth.md
Markdown
│ ├─
capabilities.md
Markdown
│ ├─
commands.md
Markdown
│ ├─
commands.template.md
Markdown
│ ├─
config.md
Markdown
│ ├─
cycle.md
Markdown
│ ├─
document.md
Markdown
│ ├─
initiative-update.md
Markdown
│ ├─
initiative.md
Markdown
│ ├─
issue.md
Markdown
│ ├─
label.md
Markdown
│ ├─
milestone.md
Markdown
│ ├─
notification.md
Markdown
│ ├─
organization-features.md
Markdown
│ ├─
project-label.md
Markdown
│ ├─
project-update.md
Markdown
│ ├─
project.md
Markdown
│ ├─
resolve.md
Markdown
│ ├─
schema.md
Markdown
│ ├─
team.md
Markdown
│ ├─
user.md
Markdown
│ ├─
webhook.md
Markdown
│ └─
workflow-state.md
Markdown
├─
▾
scripts
│ └─
generate-docs.ts
TypeScript
├─
SKILL.md
Markdown
└─
SKILL.template.md
Markdown
依赖分析 1 项
| 包名 | 版本 | 来源 | 已知漏洞 | 备注 |
|---|---|---|---|---|
linear-cli | unspecified | external CLI | 否 | External dependency - skill is a wrapper, actual CLI must be installed separately |
安全亮点
✓ No credential harvesting or exfiltration - linear auth token is documented as a user-facing command
✓ No base64 or obfuscated code execution
✓ No remote script download or pipe-to-bash patterns
✓ Network requests only to known Linear API endpoint (api.linear.app)
✓ All shell commands go through the linear CLI tool, not arbitrary subprocess execution
✓ No access to sensitive paths like ~/.ssh, ~/.aws, or .env files
✓ Well-documented skill with comprehensive reference documentation