linear-incident-runbook

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strong security boundaries, explicitly prohibiting the agent from writing credentials, customer content, or unredacted GraphQL variables to files or environment outputs.
  • [SAFE]: The runbook enforces a 'read-only first' approach to diagnosis, requiring explicit owner approval before any production mutations, data exports, or configuration changes are performed.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes incident symptoms and IDs which may be provided via untrusted user input or external monitoring data. This risk is managed through specific instructions to redact sensitive fields and maintain a mutation freeze until explicitly authorized.
  • [SAFE]: Network operations are limited to first-party Linear documentation and API endpoints, adhering to the principle of least privilege for the intended workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 08:05 PM
Security Audit — agent-trust-hub — linear-incident-runbook