implement-task-linear

Pass

Audited by Gen Agent Trust Hub on Oct 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external Linear issues, including descriptions, comments, and attachments. Crucially, it is instructed to follow 'Source' paths or URLs provided within the issue text. This untrusted data is used to define implementation logic, creating a risk that an attacker could provide an issue containing malicious instructions meant to override the agent's behavior.\n
  • Ingestion points: Linear issue description, comments, attachments, and external 'Source' URLs (referenced in SKILL.md, Step 2).\n
  • Boundary markers: Absent; there are no instructions to use delimiters or to disregard natural language instructions found within the fetched data.\n
  • Capability inventory: The skill allows for repository-wide file reads/writes and the execution of local shell commands for testing purposes.\n
  • Sanitization: No sanitization or validation of the fetched external content is specified before it enters the model's context.\n- [COMMAND_EXECUTION]: The skill requires the agent to execute local commands for verification ('run the smallest relevant test and typecheck'). If the repository's test configuration or the implementation path is influenced by a malicious injection from the Linear issue, this could lead to the execution of harmful code within the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 11, 2026, 12:27 AM