Linear
Warn
Audited by Socket on Jul 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s core capabilities fit Linear management, and most data flows target official Linear services. However, it relies on broad Bash execution, forwards API credentials through third-party tools like mcp-remote/varlock, and includes a session-JSONL image extraction workflow that expands local data access. This is not clearly malicious, but its footprint is somewhat larger and riskier than a narrowly scoped Linear skill.
Confidence: 89%Severity: 68%
Audit Metadata