prioritize

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from an external source (Linear issue titles and descriptions) and incorporates it into the logic of subagents.
  • Ingestion points: The skill fetches issue data via mcp__linear-server__list_issues and mcp__linear-server__get_issue (found in SKILL.md).
  • Boundary markers: While prompts for subagents (e.g., in references/prompts/llm-fallback-bucket.md) use structured section headers like ### Issue, they lack robust delimiters (such as random nonces) to isolate untrusted content from the agent's instructions.
  • Capability inventory: The skill has the capability to write to the local file system (reports) and modify external platform state by updating issue descriptions and posting comments on Linear.
  • Sanitization: There is no evidence of sanitization or character escaping of the Linear data before it is interpolated into prompts or written back to the platform.
  • [COMMAND_EXECUTION]: The skill performs file system operations, such as directory creation using mkdir -p and writing audit report files as described in the artifact generation section of SKILL.md. These actions are within the expected scope of a product vision auditing tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:16 AM