project-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior or security risks were identified. The instructions establish a highly constrained workflow for managing task states in Linear. The use of invariants like 'Todo is your only dispatch verb' and requirements to use a cloud proxy for writes significantly reduce the surface for unauthorized or harmful actions.- [INDIRECT_PROMPT_INJECTION]: The skill interacts with external ticket data which acts as an ingestion surface. Ingestion points: Project and ticket details are read from a database replica (SKILL.md, Step 2). Boundary markers: Absent. Capability inventory: The skill uses the linearis tool to modify ticket states and post threaded replies. Sanitization: Not explicitly documented; however, the skill's instructions limit operations to pre-defined state changes and structured communication outcomes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 09:29 PM
Security Audit — agent-trust-hub — project-orchestrator