Atlas / MCP servers / tacticlaunch / Linear

LinearCAUTION

mcp/tacticlaunch/linear-13

MCP server that enables AI assistants to interact with Linear project management system through natural language, allowing users to retrieve, create, and update issues, projects, and teams.

Verdict
CAUTION
Grade
C
Trust score
75 /100
Exposed tools
18 16r · 2w · 0d
Transport
stdio
License
MIT
Stars
147
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

A Model Context Protocol (MCP) server for the Linear GraphQL API, built for real project-management workflows — not just basic issue CRUD.

[](https://www.npmjs.com/package/@tacticlaunch/mcp-linear)

Features

MCP Linear bridges AI assistants and Linear by implementing the MCP protocol. With it you can:

  • Retrieve issues, projects, teams, cycles, milestones, roadmaps, customers, customer needs, and workspace/project/initiative/team/issue/release/cycle documents
  • Create and update issues, change status, assign, and comment
  • Manage projects, full diff-aware project and initiative update lifecycles, milestones, roadmaps, saved views, and favorites
  • Create and manage workspace webhooks, including updates and signing-secret rotation
  • Prepare OAuth app manifests and authorization URLs, issue scoped client-credentials tokens, or manage child OAuth apps when authenticated as a managing OAuth application
  • Work with templates, custom fields, and attachments
  • Work with customer records, customer statuses/tiers, and customer needs linked to issues or projects
  • Read notifications, subscriptions, sessions, audits, and integrations without leaving MCP
  • Inspect rate-limit and server health before running heavy planning sessions

See TOOLS.md for the full inventory.

MCP-native resources and prompts

The server exposes MCP resources and prompts in addition to tools, including:

  • Resources: linear://viewer, linear://organization, linear://teams, `linear://project
Read from source at commit afc93e8fd672OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add mcp-linear --env LINEAR_API_KEY=${LINEAR_API_KEY} --env LINEAR_API_TOKEN=${LINEAR_API_TOKEN} --env LINEAR_OAUTH_ACCESS_TOKEN=${LINEAR_OAUTH_ACCESS_TOKEN} --env LINEAR_OAUTH_CLIENT_ID=${LINEAR_OAUTH_CLIENT_ID} -- npx -y @tacticlaunch/[email protected]
claude-desktop
{
  "mcpServers": {
    "mcp-linear": {
      "command": "npx",
      "args": [
        "-y",
        "@tacticlaunch/[email protected]"
      ],
      "env": {
        "LINEAR_API_KEY": "${LINEAR_API_KEY}",
        "LINEAR_API_TOKEN": "${LINEAR_API_TOKEN}",
        "LINEAR_OAUTH_ACCESS_TOKEN": "${LINEAR_OAUTH_ACCESS_TOKEN}",
        "LINEAR_OAUTH_CLIENT_ID": "${LINEAR_OAUTH_CLIENT_ID}"
      }
    }
  }
}
03

Exposed tools (18)

16 read · 2 write · 0 destructive.

ToolRiskDescription
Betaread
PlatformreadBuild the platform
Projectread
SeverityreadRisk score
audiencereadOptional audience such as execs, eng, or customers
customFieldValuesreadIssue custom field values
customFieldsreadList custom field definitions
documentIdreadLinear document ID
draft-project-updatewriteDraft a project update using current project issues and documents
focusreadOptional focus area such as risks, scope, or delivery
issueCustomFieldUpdatewriteUpdate a custom field value for an issue
issueIdreadLinear issue ID or identifier
issuesreadList issues
projectIdreadLinear project ID to summarize
summarize-documentreadSummarize a Linear document and connect it to the surrounding project context
summarize-project-statusreadSummarize project status using Linear project, issue, and document resources
titlereadIssue title
triage-issuereadTriage a Linear issue using the canonical issue resource
04

Trust audit

CAUTIONgrade C · trust 75/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (5 observation(s))
Network
none-observed
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (20)

MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/cli.ts:192
print(`  Access token: ${maskToken(credentials.accessToken)}`);
MEDIUMInformation disclosure · disclose.log_secret · CWE-209, CWE-532
src/auth/cli.ts:199
print(`  Refresh token: ${credentials.refreshToken ? 'stored' : 'none'}`);
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/__tests__/auth-managed-auth.test.ts:84
token: 'refreshed-access-token',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/__tests__/auth-managed-auth.test.ts:108
token: 'refreshed-access-token',
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/__tests__/oauth-webhook-tools.test.ts:834
rotateSecretWebhook: jest.fn().mockResolvedValue({ success: true, secret: 'rotated-webhook-secret' }),
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/__tests__/oauth-webhook-tools.test.ts:854
secret: 'rotated-webhook-secret',
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/definitions/customer-tools.ts:1
import { MCPToolDefinition } from '../../types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/definitions/customer-tools.ts:7
} from '../../tool-annotations.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/definitions/cycle-tools.ts:1
import { MCPToolDefinition } from '../../types.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/definitions/cycle-tools.ts:6
} from '../../tool-annotations.js';
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/tools/definitions/document-tools.ts:1
import { MCPToolDefinition } from '../../types.js';
LOWNetwork egress · net.metadata_ip · CWE-200, CWE-319
src/__tests__/oauth-webhook-tools.test.ts:418
'https://169.254.169.254/webhooks/linear', // link-local / metadata
Why it matters. cloud metadata endpoint: the classic SSRF credential grab
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/auth-callback-server.test.ts:12
`http://127.0.0.1:${pending.port}/callback?code=auth-code-1&state=expected-state`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/auth-callback-server.test.ts:30
`http://127.0.0.1:${pending.port}/callback?code=auth-code-1&state=attacker-state`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/auth-callback-server.test.ts:46
`http://127.0.0.1:${pending.port}/callback?error=access_denied&state=expected-state`,
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/auth-callback-server.test.ts:60
const stray = await fetch(`http://127.0.0.1:${pending.port}/favicon.ico`);
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
src/__tests__/auth-callback-server.test.ts:64
`http://127.0.0.1:${pending.port}/callback?code=auth-code-2&state=expected-state`,
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@linear/sdk, @modelcontextprotocol/sdk, @types/cors, @types/express, cors, dotenv, express, graphql
Why it matters. 23 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
TOOLS.md:359
Client-credentials tokens normally last 30 days and do not include refresh tokens. Linear allows multiple active tokens only when they share the same scope set; requesting a different scope set revoke
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
TOOLS.md:351
Linear exposes managed OAuth application lifecycle operations as an alpha GraphQL surface and does not yet include first-class methods for them in `@linear/sdk`; this server therefore uses minimal raw
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha afc93e8fd672full audit observations/trust-audit/mcp-server/tacticlaunch__linear-13.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07afc93e8fd672CAUTIONC75first audit
06

Questions

What is the Linear MCP server?

MCP server that enables AI assistants to interact with Linear project management system through natural language, allowing users to retrieve, create, and update issues, projects, and teams.

What tools does Linear expose?

18 in total: 16 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Linear safe to connect to an agent?

With care. The audit graded it C (75/100) and found 20 things worth knowing before you trust this server, listed below with the exact line each was found on.

What credentials does Linear need?

It reads LINEAR_API_KEY, LINEAR_API_TOKEN, LINEAR_OAUTH_ACCESS_TOKEN, LINEAR_OAUTH_CLIENT_ID, LINEAR_OAUTH_CLIENT_SECRET and LINEAR_WEBHOOK_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Linear run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as @tacticlaunch/mcp-linear at 1.4.4.

How current is this page?

The grade is for one exact copy of the source (afc93e8fd672), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement