
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
claude-plugin-linear
Advanced tools
Claude Code skill for Linear issue, project, and team management with MCP integration
A comprehensive Claude Code skill for managing Linear issues, projects, and teams. Provides patterns for MCP tools, SDK automation, and GraphQL API access.
# Option A: Claude Plugin (Recommended)
claude plugin install github:wrsmith108/linear-claude-skill
# Option B: Manual Installation
git clone https://github.com/wrsmith108/linear-claude-skill ~/.claude/skills/linear
cd ~/.claude/skills/linear && npm install
npx tsx ~/.claude/skills/linear/scripts/setup.ts
This checks your configuration and tells you exactly what's missing.
lin_api_)# Add to shell profile
echo 'export LINEAR_API_KEY="lin_api_your_key_here"' >> ~/.zshrc
source ~/.zshrc
npx tsx ~/.claude/skills/linear/scripts/linear-ops.ts whoami
You should see your name and organization.
# Create an initiative
npx tsx scripts/linear-ops.ts create-initiative "My Project"
# Create a project
npx tsx scripts/linear-ops.ts create-project "Phase 1" "My Project"
# Create a sub-issue under a parent
npx tsx scripts/linear-ops.ts create-sub-issue ENG-100 "Add tests" "Unit tests for feature"
# Set parent-child relationships for existing issues
npx tsx scripts/linear-ops.ts set-parent ENG-100 ENG-101 ENG-102
# Update issue status
node scripts/linear-helpers.mjs update-status Done 123 124
# See all commands
npx tsx scripts/linear-ops.ts help
claude plugin add github:wrsmith108/linear-claude-skill
# Clone directly to your skills directory
git clone https://github.com/wrsmith108/linear-claude-skill ~/.claude/skills/linear
cd ~/.claude/skills/linear && npm install
{
"mcpServers": {
"linear": {
"command": "npx",
"args": ["mcp-remote", "https://mcp.linear.app/sse"],
"env": {
"LINEAR_API_KEY": "your_api_key"
}
}
}
}
Important: Always use Linear's official MCP server at
mcp.linear.app. Do NOT use deprecated community servers likelinear-mcp-server(npm) orjerhadf/linear-mcp-server(GitHub).
linear-claude-skill/
├── SKILL.md # Main skill instructions (Claude Code discovers this)
├── api.md # GraphQL API reference
├── sdk.md # SDK automation patterns
├── sync.md # Bulk sync patterns
├── docs/
│ └── labels.md # Label taxonomy documentation
├── scripts/
│ ├── linear-ops.ts # High-level operations (issues, projects, labels)
│ ├── query.ts # GraphQL query runner
│ ├── setup.ts # Configuration checker
│ ├── sync.ts # Bulk sync CLI tool
│ ├── linear-api.mjs # Direct API wrapper
│ └── lib/ # Shared utilities (taxonomy, labels, verification)
└── hooks/
└── post-edit.sh # Auto-sync hook
ALWAYS check Linear before creating projects or issues. This prevents duplicates:
# Check for existing projects
linear projects list | grep -i "phase\|feature-name"
# Check for existing issues
linear issues list --filter "title:keyword"
See SKILL.md → "Discovery Before Creation" for the full checklist.
ALWAYS verify codebase state before accepting issue scope at face value.
Issue descriptions may be outdated or speculative. APIs or features may already be implemented!
# Before starting "implement API" issues:
ls src/pages/api/admin/members/ # Check if files exist
grep -r "test.skip" tests/ # Check if tests are just skipped
Key Lesson: Issues describing "missing" features may already be implemented. The real work is often un-skipping tests and fixing assertions, not reimplementing.
See SKILL.md → "Codebase Verification Before Work" for the full checklist.
The Linear MCP server has known reliability issues (34% timeout rate due to SSE idle timeouts):
| Operation | MCP Reliability | Recommendation |
|---|---|---|
| Create issue | ✅ Reliable | Use MCP |
| Search issues | ⚠️ Times out | Use GraphQL |
| Update status | ⚠️ Unreliable | Use GraphQL |
| Add comment | ❌ Broken | Use GraphQL |
See SKILL.md for GraphQL workaround patterns and root cause explanation.
Linear has TWO text fields — using the wrong one causes blank displays:
| Field | Limit | Shows In |
|---|---|---|
description | 255 chars | List views, tooltips |
content | Unlimited | Main detail panel |
Always set BOTH when creating projects.
Status UUIDs are workspace-specific. Query your workspace:
query { projectStatuses { nodes { id name } } }
Common statuses: Backlog, Planned, In Progress, Completed, Canceled
Organize issues into parent-child hierarchies for better tracking:
# Create a sub-issue under a parent issue
# Inherits team and project from parent automatically
npx tsx scripts/linear-ops.ts create-sub-issue <parent> <title> [description] [--priority 1-4] [--labels label1,label2]
# Set existing issues as children of a parent
npx tsx scripts/linear-ops.ts set-parent <parent> <child1> <child2> ...
# List all sub-issues of a parent
npx tsx scripts/linear-ops.ts list-sub-issues <parent>
When to use sub-issues:
A standardized label system for consistent issue categorization across projects:
# Show full taxonomy (25 labels across 3 categories)
npx tsx scripts/linear-ops.ts labels taxonomy
# Validate label combinations
npx tsx scripts/linear-ops.ts labels validate "feature,security,breaking-change"
# Suggest labels based on issue title
npx tsx scripts/linear-ops.ts labels suggest "Fix XSS vulnerability in login form"
# Show agent recommendations for labels
npx tsx scripts/linear-ops.ts labels agents "security,performance"
Label Categories:
feature, bug, refactor, chore, spikesecurity, backend, frontend, testing, infrastructure, mcp, cli, etc.blocked, breaking-change, tech-debt, needs-split, good-first-issueSee docs/labels.md for the complete taxonomy guide.
Add clickable links to projects/initiatives:
mutation {
entityExternalLinkCreate(input: {
url: "https://github.com/org/repo/docs/phase-1.md",
label: "Implementation Doc",
projectId: "<uuid>"
}) { success }
}
Track Definition of Done:
mutation {
projectMilestoneCreate(input: {
projectId: "<uuid>",
name: "DoD: Testing",
description: "Unit tests, E2E tests, 100% coverage"
}) { success }
}
Post status updates to a project's Updates tab:
# Using SDK script (recommended)
LINEAR_API_KEY=lin_api_xxx npx tsx scripts/create-project-update.ts "Project Name" "## Update\n\nBody" onTrack
Health options: onTrack, atRisk, offTrack
See SKILL.md for full documentation and GraphQL examples.
Create a high priority issue titled "Fix authentication bug" in the ENG team
mutation {
projectUpdate(id: "<project-uuid>", input: {
statusId: "<status-uuid>" # Get from projectStatuses query
}) { success }
}
See sdk.md for TypeScript patterns for loops, filtering, and batch updates.
Synchronize code changes with Linear issues in bulk:
# Update multiple issues to Done
npx ts-node scripts/sync.ts --issues SMI-432,SMI-433,SMI-434 --state Done
# Update project status after phase completion
npx ts-node scripts/sync.ts --project "Phase 11" --state completed
# Verify sync completed
npx ts-node scripts/sync.ts --verify SMI-432,SMI-433 --expected-state Done
Spawn a parallel agent for autonomous sync via Task tool:
Task({
description: "Sync Phase 11 to Linear",
prompt: "Update SMI-432,433,434 to Done. Update project to completed.",
subagent_type: "general-purpose"
})
Auto-suggest sync after code edits. Add to .claude/settings.json:
{
"hooks": {
"PostToolUse": [{
"matcher": "Write|Edit",
"hooks": [{
"type": "command",
"command": "bash ~/.claude/skills/linear/hooks/post-edit.sh"
}]
}]
}
}
See sync.md for complete patterns including AgentDB integration.
Contributions welcome! Please submit issues and PRs to improve the skill.
MIT License — See LICENSE
Created for the Claude Code community. Patterns developed through real-world project management workflows.
FAQs
Claude Code skill for Linear issue, project, and team management with MCP integration
The npm package claude-plugin-linear receives a total of 0 weekly downloads. As such, claude-plugin-linear popularity was classified as not popular.
We found that claude-plugin-linear demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.