Linear StreamableBLOCK
MCP Server for interacting with Linear API. Written in TypeScript, Node and Hono.dev
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This server is a remote Model Context Protocol (MCP) server for Linear. A model can use it to find, read, create and update issues, comments and projects, and to read teams, users and cycles. The server runs on Cloudflare Workers and on Bun. It uses the MCP server template 2.1 and the official MCP TypeScript SDK 2.3.0.
The server URL is the deployed Worker's MCP_PUBLIC_URL, for example https://linear-mcp..workers.dev/mcp.
The server uses protocol version 2026-07-28. It also accepts clients that use the 2025 protocol versions.
[!WARNING] You connect this server to your MCP client at your own risk. A model can make mistakes. Examine what the tools do, and examine the changes in Linear. The write tools change issues, comments and projects in your workspace.
Tools
5d6cb9b8a6afOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add linear-mcp --env LINEAR_TEST_TOKEN=${LINEAR_TEST_TOKEN} -- npx -y linear-mcp{
"mcpServers": {
"linear-mcp": {
"command": "npx",
"args": [
"-y",
"linear-mcp"
],
"env": {
"LINEAR_TEST_TOKEN": "${LINEAR_TEST_TOKEN}"
}
}
}
}Exposed tools (1)
1 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
Engineering | read | Core engineering team |
Trust audit
BLOCKgrade F · trust 54/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (4 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (3 observation(s))
- Dependencies
- pinned
- Secrets in source
- found
Findings (21)
exec(input?: (string | URLPatternInit), baseURL?: string): URLPatternResult | null;
exec(cmd: string[], options?: ContainerExecOptions): Promise<ExecProcess>;
exec(query: string): Promise<D1ExecResult>;
logger.error(`${options.provider.name} token refresh failed; using the current token`, {# Defaults to http://127.0.0.1:$PORT/mcp outside production; required in production.
# MCP_PUBLIC_URL=http://127.0.0.1:3000/mcp
OAUTH_ISSUER_URL=http://127.0.0.1:3000
OAUTH_AUTHORIZATION_URL=http://127.0.0.1:3000/authorize
OAUTH_TOKEN_URL=http://127.0.0.1:3000/token
const TOKEN = 'a-long-random-shared-secret';
import { providerToken } from '../../oauth/verifier';import type { Logger } from '../../platform/logger';import { type ToolErrorResult, toolError } from '../../platform/primitives';import type { Deps } from '../../server';import { createIssues } from '../../src/tools/create-issues';const binary = atob(base64.padEnd(Math.ceil(base64.length / 4) * 4, '='));
atob(data: string): string;
declare function atob(data: string): string;
The Worker writes JSON logs to Workers Logs. A tool error that the model sees as "internal error (reference ...)" has its details in the logs under that reference. Linear API errors are shown to the m
**Issued tokens (Workers KV `TOKENS`).** Each record is written twice, as `rs:access:<access token>` and `rs:refresh:<refresh token>`:
docs/comparison-hd.gif
Gates applied: no_behavioural_pass.
5d6cb9b8a6affull audit observations/trust-audit/mcp-server/iceener__linear-streamable.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 5d6cb9b8a6af | BLOCK | F | 54 | first audit |
Questions
What is the Linear Streamable MCP server?
MCP Server for interacting with Linear API. Written in TypeScript, Node and Hono.dev
What tools does Linear Streamable expose?
1 in total: 1 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Linear Streamable safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (54/100) and found 3 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does Linear Streamable need?
It reads LINEAR_TEST_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Linear Streamable run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as linear-mcp.
How current is this page?
The grade is for one exact copy of the source (5d6cb9b8a6af), read on 2026-10-07. The repository is watched and re-audited when it changes.