ClawAudit verdict
linear-graphql-skill
The skill appears to be a legitimate Linear GraphQL API operator, allowing users to query and manage issues, projects, and teams. No malicious or deceptive behavior is detected.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (3)
Possible hardcoded credential
SKILL.md · prose · downgraded · API_KEY="lin_api_XXX
HTTP request to bare IP address — common in malicious payloads
references/usage-patterns.md · code · http://127.0.0.1
Social engineering — falsely claims user authorization
skill-card.md · prose · downgraded · the user has configured
Permissions & capabilities
No declared permissions — minimal attack surface.
Is this flag fair?
Thanks — recorded.