linear
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external Linear API responses, such as issue titles and comments, which could potentially contain instructions aimed at manipulating the agent's logic. Ingestion points: Linear API responses in SKILL.md (e.g., assignedIssues, issueSearch, issue). Boundary markers: None present in the prompt templates. Capability inventory: Shell execution (curl, jq) and environment variable access. Sanitization: No explicit sanitization or escaping of the fetched content is provided in the instructions.
- [COMMAND_EXECUTION]: The skill utilizes standard system-level commands such as curl, jq, and PowerShell's Invoke-RestMethod for API interactions.
- [DATA_EXFILTRATION]: The skill performs network operations to the official Linear API endpoint (api.linear.app) to manage project data.
Audit Metadata