Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add mcp/arclabs-studio/arclineargithub-mcp/arc-linear-github-mcpgit clone --depth 1 https://github.com/arclabs-studio/ARCLinearGitHub-MCPGrade A, and why
arc-linear-github-mcp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"arc-linear-github-mcp": {
"command": "uvx",
"args": [
"arc-linear-github-mcp"
],
"env": {
"LINEAR_API_KEY": "",
"GITHUB_TOKEN": "",
"GITHUB_ORG": "",
"DEFAULT_PROJECT": "",
"DEFAULT_REPO": "",
"LINEAR_WORKSPACES": ""
}
}
}What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 16 lines scan A 4bf1ec03068a
arc-linear-github-mcp is an MCP server published in the GitHub repository arclabs-studio/ARCLinearGitHub-MCP (0 stars, last pushed 3mo ago), licensed MIT. Its token cost is not measured: an MCP server costs its tool schemas, not its config file. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other mcp servers, from other repositories
linear
Linear MCP — wraps the Linear GraphQL API (OAuth). Remote server at gateway.pipeworx.io.
linear-mcp-lean
Self-hosted MCP server wrapping Linear's GraphQL API with response-shape control — lean reads, minimal write acks, drop-in tool names. Runs locally from the linear-mcp-lean npm package.
abscissa
A safety-aware MCP server for Linear. Runs locally from the abscissa Python package. Needs 1 environment variable to run.
linear-context-server
A Model Context Protocol server. Runs locally from the @kljn/linear-context-server npm package.
task-master-ai
A task management system for ambitious AI-driven development that doesn't overwhelm and confuse Cursor. Runs locally from the task-master-ai npm package. Needs 9 environment variables to run.
smartsuite
MCP server "smartsuite" as configured in SmartSuiteFoundry/smartsuite-mcp-server. Launched with smartsuite-mcp. Needs 4 environment variables to run.