linear-finish-install
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to modify local configuration files, including
~/.claude/CLAUDE.md,~/.codex/AGENTS.md, and.cursor/rules. These writes are used to install persistent operational guidelines that remain active across sessions. \n- [PROMPT_INJECTION]: Through theALWAYS_ON.mdfile, the skill implements a persistence mechanism that instructs the agent to treat an external service (Linear) as the default 'Source of Truth'. This ensures consistent behavioral compliance with the tracking pack's methodology. \n- [PROMPT_INJECTION]: The skill establishes a surface for indirect prompt injection by mandating that the agent follow external Linear project data as its primary source of truth. \n - Ingestion points: External Linear workspace data accessed via MCP tools (e.g., issues, milestones, teams). \n
- Boundary markers: None identified; the agent is instructed to directly follow the external 'discipline'. \n
- Capability inventory: File system writes (config updates) and MCP tool execution (Linear read/write). \n
- Sanitization: No explicit sanitization or validation of the external Linear content is defined in the instructions. \n- [SAFE]: No malicious obfuscation, credential theft, or unauthorized network operations were detected. All external references target well-known developer services (Linear, Cursor, Claude).
Audit Metadata