human-first-linear
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources (Linear issues, notes, or source material) that are not controlled by the skill itself, creating a potential surface for indirect prompt injection.
- Ingestion points: The workflow specifically instructs the agent to read "live issues," "notes," or "source material" (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or clear boundaries to isolate the external content from the agent's system instructions.
- Capability inventory: The skill possesses write capabilities through the "Live edit" mode, which allows the agent to update and save changes back to the Linear platform (SKILL.md).
- Sanitization: There are no explicit instructions for the agent to sanitize, filter, or ignore instructions that might be embedded within the issue text being processed.
Audit Metadata