linear
Warn
Audited by Socket on Jul 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent, but the install and execution trust story is not: the skill references a `linear` CLI and auth flow that were not confirmed in official docs, while the cited npm package appears to expose a different command and is old/unpinned. Because the skill would authenticate and send project data through that local CLI, the unclear binary provenance materially raises supply-chain and credential-forwarding risk.
Confidence: 86%Severity: 78%
Audit Metadata