prioritize
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from an external source (Linear issue titles and descriptions) and incorporates it into the logic of subagents.
- Ingestion points: The skill fetches issue data via
mcp__linear-server__list_issuesandmcp__linear-server__get_issue(found inSKILL.md). - Boundary markers: While prompts for subagents (e.g., in
references/prompts/llm-fallback-bucket.md) use structured section headers like### Issue, they lack robust delimiters (such as random nonces) to isolate untrusted content from the agent's instructions. - Capability inventory: The skill has the capability to write to the local file system (reports) and modify external platform state by updating issue descriptions and posting comments on Linear.
- Sanitization: There is no evidence of sanitization or character escaping of the Linear data before it is interpolated into prompts or written back to the platform.
- [COMMAND_EXECUTION]: The skill performs file system operations, such as directory creation using
mkdir -pand writing audit report files as described in the artifact generation section ofSKILL.md. These actions are within the expected scope of a product vision auditing tool.
Audit Metadata