linear-automation

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from Linear issues and comments, creating a potential surface for indirect prompt injection attacks.
  • Ingestion points: Tools such as LINEAR_GET_LINEAR_ISSUE, LINEAR_LIST_LINEAR_ISSUES, and LINEAR_SEARCH_ISSUES (referenced in SKILL.md) ingest content from external Linear workspaces into the agent's context.
  • Boundary markers: The instructions do not specify the use of boundary markers or explicit prompts to ignore instructions embedded within the retrieved issue descriptions or comments.
  • Capability inventory: The skill includes write-access tools such as LINEAR_CREATE_LINEAR_ISSUE, LINEAR_UPDATE_ISSUE, and the ability to execute GraphQL mutations via LINEAR_RUN_QUERY_OR_MUTATION (referenced in SKILL.md).
  • Sanitization: No explicit sanitization or validation steps are defined for processing external issue content before it is used to inform further agent actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 11:45 PM