multi-version-compliance
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources such as Linear task descriptions and GitHub PR content, which could contain malicious instructions designed to influence the agent's behavior during code modification or testing phases.
- Ingestion points: The skill fetches issue details and comments using
mcp__linear-server__get_issueandmcp__linear-server__list_commentsin Phase 1. It also reads pull request data and diffs usinggh pr viewandgh pr diffin the Review mode. - Boundary markers: The instructions include a "Linear-fetching protocol" that verifies the issue title against a specific regex pattern (
[multi-version][P##] ...) and checks the milestone. It also requires the agent to restate decisions and findings to the user. - Capability inventory: The skill uses the
Bashtool to executenpx nx testandnpx nx format, and theWriteandEdittools to modify source code in the repository. - Sanitization: The skill employs a mandatory "User OK gate" after Phase 2, where the agent must wait for explicit user approval before proceeding to Phase 3 (Implement), which involves branching and file edits.
Audit Metadata