skills/stablyai/orca/linear-tickets/Gen Agent Trust Hub

linear-tickets

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill acts as a configuration and discovery stub for the Orca CLI. It provides logic to resolve the correct executable path (orca, orca-ide, or orca-dev) based on the environment to ensure correct tool execution and avoid conflicts with system utilities. No malicious code, exfiltration patterns, or obfuscation techniques were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill proactively addresses potential indirect prompt injection vulnerabilities by defining how the agent should handle external data.
  • Ingestion points: Linear ticket text, comments, and attachments described in the skill's intended use case.
  • Boundary markers: Includes an explicit instruction to treat external content as untrusted data and never as instructions.
  • Capability inventory: The skill facilitates ticket workflow transitions, searching, PR/MR linking, and follow-up ticket creation via the Orca CLI.
  • Sanitization: The skill relies on prompt-level instructions to maintain logical boundaries between data and instructions; no programmatic sanitization is defined in this discovery stub.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:02 AM
Security Audit — agent-trust-hub — linear-tickets