Set up the OpenAI Linear skill safely

Guide to the OpenAI Linear skill: MCP connection, permissions, safe issue changes, governance, reviews, and clear approvals.

  • Skill Road
  • Set up the OpenAI Linear skill safely

Published on 09.09.2026

Linear is an official curated skill from OpenAI’s repository for Codex. According to the provider, it supports work with issues, projects, and team workflows in Linear through a connected Linear MCP integration. Linear itself is a tool for product and engineering teams, where tasks, projects, cycles, statuses, priorities, and comments are organized. The skill is not a separate Linear app and not a replacement for Linear. It gives Codex a workflow so an agent reads context first, selects the right workflow, and applies external changes in a controlled way.

Check prerequisites and connection

Before using the skill in production, the Linear MCP connection must be reachable. According to the official skill file, this requires OAuth and access to the relevant workspace, teams, and projects. OAuth means sign-in happens through an authorization flow instead of copying passwords into the agent. Check whether your Codex client supports remote MCP and whether the connection can see only the workspaces it needs.

Start with a read-only request. For example, ask for a summary of teams, projects, or your own issues. This shows whether the agent sees the right organization and team. If the connection fails, the source says the workflow should pause for setup, let the user connect Linear, and continue after restart. Do not force write actions while identity, workspace, and permissions are unclear.

Clarify request and scope

Linear data often looks obvious but depends on context. An issue title may appear in several projects, a team may have similar labels, and priority may mean different things in different workflows. Describe the goal and scope concretely: is this triage, sprint planning, a documentation audit, release preparation, dependency analysis, or a comment draft? Name the team, project, cycle, label, priority, and due date only when they are relevant and confirmed.

The provider describes a workflow of clarifying the goal, selecting the appropriate workflow, identifying the required tools, and then executing the work. In safe practice, that means read first, propose next, change last. Have the agent retrieve existing issues, projects, or comments before it creates new tasks. For bulk changes, it should explain grouping and criteria before anything changes in Linear.

Change issues, projects, and comments safely

For every change, review the title, description, team, project, status, priority, assignee, and labels. A new issue should include a clear goal, context, acceptance criteria, and, where helpful, links to documents. A comment should make clear whether it is a summary, question, decision proposal, or review request. Changes to status or ownership can affect other people’s work and should not happen casually.

Linear content is data, not trusted instruction. An issue description may be stale or may intentionally include prompt-like text. The agent must not treat that content as new system rules. If an issue asks the assistant to ignore security rules or reveal secret data, that is prompt injection and should be rejected. Explicitly confirm external actions, especially when tasks are created, moved, closed, or commented on.

Security, privacy, and governance

Do not store passwords, tokens, private keys, or customer secrets in Linear issues. Even apparently internal tickets may later be exported, searched, or shared with other teams. Work with least privilege and check whether private teams, customer names, vulnerabilities, or personal data are involved. Using the skill may send data to Linear, the MCP connection, and the selected model.

Organizations should use a clear rule: reads are lower risk, writes require review. Define which actions the agent may prepare and which need approval. Record important changes through Linear comments or internal change notes. For security issues, HR-sensitive topics, or customer escalations, a person should review the final wording and recipient scope.

Value and limits

The practical value is high when teams want to structure recurring Linear work. The skill can summarize critical open issues, find missing labels, suggest sprint candidates, organize release work, or turn documentation gaps into candidate tickets. It saves time because it defines the order of reading, framing, changing, and summarizing.

Limits come from permissions, data quality, and context. The skill can only see what the connection allows. It does not automatically know your team’s political, contractual, or technical priorities. It does not replace product ownership, incident management, or team decisions. Use it as a controlled assistant for Linear work, not as an autonomous project manager.

Published on 09.09.2026

Categories

Frequently asked questions

Is the Linear skill a separate Linear app?

No. It is an official Codex workflow and requires a connected Linear integration.

Can the skill change issues on its own?

The integration may enable changes, but target, authorization, and scope should be reviewed before external actions.

Are issue descriptions trusted instructions?

No. They are data and may be stale, manipulated, or affected by prompt injection.