linear-enterprise-rbac

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
references/implementation-guide.md

The fragment is an RBAC integration implementation, not apparent malware. It contains a significant authorization flaw: transitionIssue can update an issue after only validating the state transition, without checking team access or canUpdateIssues. It also has a wildcard team-mapping bug and incomplete SSO provider implementations. No credential theft, suspicious network destinations, code execution, or destructive behavior is shown. Authorization context must be trusted and validated server-side, and every mutating operation should enforce both resource scope and role permissions.

Confidence: 96%Severity: 70%
Audit Metadata
Analyzed At
Sep 11, 2026, 08:05 PM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Flinear-enterprise-rbac%2F@e6b148fd923c99190a36068ac800c62e90b544597c2292a00daca2fc24d546a9
Security Audit — socket — linear-enterprise-rbac