managing-linear

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches Linear issue management, but it relies on an unpinned third-party personal CLI executed through `npx -y` and passes Linear API credentials into that code. Data flows seem consistent with Linear usage and there is no clear proxy exfiltration or hidden behavior, so this is not confirmed malware; the main risk is supply-chain trust plus credential forwarding to non-Linear software.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Mar 28, 2026, 10:18 PM
Package URL
pkg:socket/skills-sh/bnadlerjr%2Fdotfiles%2Fmanaging-linear%2F@c799c4ce293f4df3fc930422cd71724bfae4b5c2
Security Audit — socket — managing-linear