linear
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local shell script located at 'skills/obsidian/second-brain/scripts/vault.sh' to mirror task data. This script is passed arguments like task titles and IDs which are retrieved from the external Linear platform.
- [PROMPT_INJECTION]: The skill processes untrusted data from Linear issues, including titles, descriptions, and comments, creating an attack surface for indirect prompt injection. 1. Ingestion points: Issue data enters the agent context via 'list/search issues' and 'get issue' tools. 2. Boundary markers: The instructions do not define delimiters or specific safety instructions to ignore embedded commands in Linear data. 3. Capability inventory: The skill has the ability to read and write to Linear via MCP tools and execute the 'vault.sh' local script. 4. Sanitization: There is no evidence of data validation or sanitization before passing external task information to the vault script.
Audit Metadata