linear-finish-install

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to modify local configuration files, including ~/.claude/CLAUDE.md, ~/.codex/AGENTS.md, and .cursor/rules. These writes are used to install persistent operational guidelines that remain active across sessions. \n- [PROMPT_INJECTION]: Through the ALWAYS_ON.md file, the skill implements a persistence mechanism that instructs the agent to treat an external service (Linear) as the default 'Source of Truth'. This ensures consistent behavioral compliance with the tracking pack's methodology. \n- [PROMPT_INJECTION]: The skill establishes a surface for indirect prompt injection by mandating that the agent follow external Linear project data as its primary source of truth. \n
  • Ingestion points: External Linear workspace data accessed via MCP tools (e.g., issues, milestones, teams). \n
  • Boundary markers: None identified; the agent is instructed to directly follow the external 'discipline'. \n
  • Capability inventory: File system writes (config updates) and MCP tool execution (Linear read/write). \n
  • Sanitization: No explicit sanitization or validation of the external Linear content is defined in the instructions. \n- [SAFE]: No malicious obfuscation, credential theft, or unauthorized network operations were detected. All external references target well-known developer services (Linear, Cursor, Claude).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 10:01 PM
Security Audit — agent-trust-hub — linear-finish-install