onboarding-coordination

Pass

Audited by Gen Agent Trust Hub on May 2, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface as it is designed to interact with external data from Linear (issue descriptions, comments, and project plans).
  • Ingestion points: Data enters the agent context through the mcp__linear__* toolset and the Read tool as referenced in SKILL.md and reference/INDEX.md.
  • Boundary markers: None identified in the provided documentation to delimit external data from agent instructions.
  • Capability inventory: The skill has access to powerful tools including Bash, Write, and the full suite of mcp__linear__* tools for task management.
  • Sanitization: No explicit sanitization or input validation logic is described in the provided files.
  • [COMMAND_EXECUTION]: The skill explicitly allows the use of the Bash tool in its configuration. This is consistent with its stated purpose of environment setup and onboarding automation, but users should be aware that the agent can execute shell commands to fulfill its tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
May 2, 2026, 07:42 AM
Security Audit — agent-trust-hub — onboarding-coordination