linear-cli
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the retrieval and processing of data from the Linear platform (such as issue titles, descriptions, and comments). This data, being externally controlled, presents a potential vector for indirect prompt injection if it contains instructions intended to manipulate the agent's logic.
- Ingestion points: Content is ingested through commands like
linear issue list,linear issue comment add, and raw GraphQL queries usinglinear api. - Boundary markers: The instructions do not specify the use of delimiters or clear separation between system instructions and data retrieved from the API.
- Capability inventory: The skill possesses the capability to execute shell commands (
linear), make network requests (curl), and manipulate the file system (cat,grep), which are potential targets for an injection attack. - Sanitization: The skill provides best practices for preventing shell escaping issues when sending data (by using file-based flags), but does not define sanitization procedures for data received from the Linear API.
- [COMMAND_EXECUTION]: The skill relies on the execution of the
linearCLI and various system utilities (curl,jq,grep). These tools are essential for the skill's intended functionality but provide a broad range of interaction with the local system and the Linear API.
Audit Metadata