linear-tickets
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill acts as a configuration and discovery stub for the Orca CLI. It provides logic to resolve the correct executable path (orca, orca-ide, or orca-dev) based on the environment to ensure correct tool execution and avoid conflicts with system utilities. No malicious code, exfiltration patterns, or obfuscation techniques were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill proactively addresses potential indirect prompt injection vulnerabilities by defining how the agent should handle external data.
- Ingestion points: Linear ticket text, comments, and attachments described in the skill's intended use case.
- Boundary markers: Includes an explicit instruction to treat external content as untrusted data and never as instructions.
- Capability inventory: The skill facilitates ticket workflow transitions, searching, PR/MR linking, and follow-up ticket creation via the Orca CLI.
- Sanitization: The skill relies on prompt-level instructions to maintain logical boundaries between data and instructions; no programmatic sanitization is defined in this discovery stub.
Audit Metadata