personal-triage

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface (Category 8) because it processes untrusted data from Linear issue titles, descriptions, and comments. \n
  • Ingestion points: Data enters the context through Linear issues and comments via list_issues and get_issue tools.\n
  • Boundary markers: No explicit markers or instructions are used to distinguish issue content from agent instructions.\n
  • Capability inventory: The skill can modify Linear issues and is directed to read local files or repositories if referenced in task descriptions.\n
  • Sanitization: There is no evidence of sanitization or validation of the ingested issue data.\n- [DATA_EXFILTRATION]: The skill has the capability to read local files if they are referenced in Linear tasks. While this presents a theoretical data exposure surface, it is a functional requirement for triaging development tasks and no unauthorized exfiltration was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:29 AM
Security Audit — agent-trust-hub — personal-triage