linear

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @membranehq/cli package from the NPM registry. This is a vendor-owned resource used for secure platform communication and authentication management.\n- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by retrieving and processing external data from Linear issues and comments.\n
  • Ingestion points: Data enters the agent context through CLI commands like membrane action run and membrane request as seen in SKILL.md.\n
  • Boundary markers: The instructions do not define specific delimiters to separate untrusted data from system instructions.\n
  • Capability inventory: The agent has the capability to perform network requests and data modifications via the Membrane CLI across all integration scripts.\n
  • Sanitization: The skill relies on default agent behavior as there are no explicit sanitization or filtering steps for the ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 04:22 AM
Security Audit — agent-trust-hub — linear