linear
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content such as issue titles, descriptions, and comments retrieved from the Linear API, which constitutes untrusted external data.
- Ingestion points: The agent retrieves external content using commands like
linear issue view,linear issues list,linear search, andlinear issue comment listas described inSKILL.md. - Boundary markers: The instructions do not define specific delimiters or warnings for the agent to distinguish between its own instructions and the content retrieved from Linear.
- Capability inventory: The skill utilizes
Bashtools (linear,git,gh,curl,jq,grep,cat) with capabilities to read/write local files and perform network operations. - Sanitization: There are no explicit instructions for sanitizing or validating the data fetched from the API before it is processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill documentation recommends the installation of an external Node.js package from a third-party repository.
- Evidence:
SKILL.mdspecifies the installation commandnpm install -g @0xbigboss/linear-cliin the setup section. - [COMMAND_EXECUTION]: The skill relies on executing the
linearCLI and other shell utilities to perform management tasks. - Evidence: The
allowed-toolssection inSKILL.mdpermits variousBashcommands, and the body of the skill provides numerous examples of shell-based interactions with the Linear platform, including git workflow integration and file system operations.
Audit Metadata