Atlas / MCP servers / cline / Linear

LinearSAFE

mcp/cline/linear-19

a private MCP server for accessing Linear

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
22 11r · 8w · 3d
Transport
stdio
License
—
Stars
134
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

An MCP server for interacting with Linear's API. This server provides a set of tools for managing Linear issues, projects, and teams through Cline.

Setup Guide

1. Environment Setup

  1. Clone the repository
  2. Install dependencies:
npm install
  1. Copy .env.example to .env:
cp .env.example .env

2. Authentication

The server supports two authentication methods:

API Key (Recommended)

  1. Go to Linear Settings
  2. Navigate to the "Security & access" section
  3. Find the "Personal API keys" section
  4. Click "New API key"
  5. Give the key a descriptive label (e.g. "Cline MCP")
  6. Copy the generated token immediately
  7. Add the token to your .env file:
LINEAR_API_KEY=your_api_key

OAuth Flow (Alternative) *NOT IMPLEMENTED*

  1. Create an OAuth application at https://linear.app/settings/api/applications
  2. Configure OAuth environment variables in .env:
LINEAR_CLIENT_ID=your_oauth_client_id
LINEAR_CLIENT_SECRET=your_oauth_client_secret
LINEAR_REDIRECT_URI=http://localhost:3000/callback

3. Running the Server

  1. Build the server:
npm run build
  1. Start the server:
npm start

4. Cline Integration

  1. Open your Cline MCP settings file:
  2. macOS: ~/Library/Application Support/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json
  3. Windows: %APPDATA%/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json
  4. Linux: ~/.config/Code/User/globalStorage/saoudrizwan.claude-dev/settings/cline_mcp_settings.json
  1. Add the Linear MCP server configuration:
{
"mcpServers": {
"linear": {
"command": "node",
"args": ["/path/to/linear-mcp/build/index.js"],
"env": {
"LINEAR_API_KEY": "your_personal_access_token"
},
"disabled": false,
"autoApprove": []
}
Read from source at commit 3a285248b732OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add linear-mcp --env LINEAR_API_KEY=${LINEAR_API_KEY} --env LINEAR_AUTH_CODE=${LINEAR_AUTH_CODE} --env LINEAR_CLIENT_SECRET=${LINEAR_CLIENT_SECRET} --env LINEAR_REFRESH_TOKEN=${LINEAR_REFRESH_TOKEN} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "linear-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "LINEAR_API_KEY": "${LINEAR_API_KEY}",
        "LINEAR_AUTH_CODE": "${LINEAR_AUTH_CODE}",
        "LINEAR_CLIENT_SECRET": "${LINEAR_CLIENT_SECRET}",
        "LINEAR_REFRESH_TOKEN": "${LINEAR_REFRESH_TOKEN}"
      }
    }
  }
}
03

Exposed tools (22)

11 read · 8 write · 3 destructive. Blast radius: 3 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
linear_authreadInitialize OAuth flow with Linear
linear_auth_callbackreadHandle OAuth callback
linear_bulk_update_issueswriteUpdate multiple issues at once
linear_create_commentwriteCreate a new comment on an issue or reply to an existing comment
linear_create_issuewriteCreate a new issue in Linear
linear_create_issueswriteCreate multiple issues at once
linear_create_project_milestonewriteCreate a new project milestone in Linear
linear_create_project_milestoneswriteCreate multiple project milestones at once
linear_create_project_with_issueswriteCreate a new project with associated issues. Note: Project requires teamIds (array) not teamId (single value).
linear_delete_issuedestructiveDelete an issue
linear_delete_issuesdestructiveDelete multiple issues
linear_delete_project_milestonedestructiveDelete a project milestone
linear_get_issue_commentsreadGet comments for a specific issue, including threaded replies
linear_get_projectreadGet project information
linear_get_project_milestonereadGet information about a specific project milestone
linear_get_project_milestonesreadGet all milestones for a specific project
linear_get_teamsreadGet all teams with their states and labels
linear_get_userreadGet current user information
linear_search_issuesreadSearch for issues with filtering and pagination
linear_search_project_milestonesreadSearch for project milestones with filtering and pagination
linear_search_projectsreadSearch for projects by name
linear_update_project_milestonewriteUpdate an existing project milestone
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (8)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
linear_delete_issue, linear_delete_issues, linear_delete_project_milestone
Why it matters. 3 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/__tests__/config/jest.setup.ts:3
import type { LinearGraphQLClient } from '../../graphql/client';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/handlers/base.handler.ts:2
import { LinearAuth } from '../../auth.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/handlers/base.handler.ts:3
import { LinearGraphQLClient } from '../../graphql/client.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/handlers/handler.factory.ts:1
import { LinearAuth } from '../../auth.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/core/handlers/handler.factory.ts:2
import { LinearGraphQLClient } from '../../graphql/client.js';
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@graphql-typed-document-node/core, @linear/sdk, @modelcontextprotocol/sdk, graphql, graphql-tag, @types/dotenv, @types/express, @types/jest
Why it matters. 17 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 3a285248b732full audit observations/trust-audit/mcp-server/cline__linear-19.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-073a285248b732SAFEB89first audit
06

Questions

What is the Linear MCP server?

a private MCP server for accessing Linear

What tools does Linear expose?

22 in total: 11 read-only, 8 that write, and 3 that can delete or overwrite (linear_delete_issue, linear_delete_issues, linear_delete_project_milestone). Every one is listed on this page with its risk.

Is Linear safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 3 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Linear need?

It reads LINEAR_API_KEY, LINEAR_AUTH_CODE, LINEAR_CLIENT_SECRET and LINEAR_REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Linear run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as linear-mcp at 1.0.0.

How current is this page?

The grade is for one exact copy of the source (3a285248b732), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement