Back to skill

Security audit

Clawbounty 2 Linear

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims for Linear, but it gives an agent live read/write authority over workspace issues without strong confirmation or secret-handling guidance.

Install only where the agent is allowed to read and change Linear data. Use the least-privileged Linear key available, keep it out of tracked files and shared logs, and require explicit review before any create, update, comment, or bulk mutation.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.