linear
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
linearisCLI tool using the commandbun add -g linearis. This fetches code from a public package registry that is not part of the trusted vendors list. - [COMMAND_EXECUTION]: All core functionalities (listing, searching, creating, and updating issues) are performed by executing shell commands through the
linearisCLI. - [INDIRECT_PROMPT_INJECTION]: The skill reads content from Linear issues, such as titles, descriptions, and comments. This data is externally controlled and could contain hidden instructions that influence the agent's subsequent actions, potentially leading to unintended modifications or data exposure within the Linear workspace.
Audit Metadata