soloscrum-tracker-linear-create-subtask

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the user (title and body inputs) which are then processed by the mcp__claude_ai_Linear__save_issue tool to create subtasks in Linear. This constitutes an ingestion surface where malicious instructions could be embedded in task descriptions. However, this is a standard workflow for project management automation and does not represent a high-risk scenario.
  • [COMMAND_EXECUTION]: The skill instructions define specific steps for interacting with the Linear API via MCP tools (list_issues, save_issue). All operations are performed within the scope of authorized project management tools and do not involve shell command execution or unauthorized system access.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 05:05 AM
Security Audit — agent-trust-hub — soloscrum-tracker-linear-create-subtask