linear-methodology

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from Linear issues, comments, and repository files (git logs, CHANGELOGs, roadmaps), creating an indirect prompt injection surface. This is proactively addressed by a 'Trust Boundary' section (§0 in METHODOLOGY.md) that instructs the agent to treat project content as untrusted data and not to follow instructions embedded within it. Mandatory Evidence Chain: Ingestion points include all Linear read tools and repository history; Boundary markers are present in the Trust Boundary section; Capability inventory includes Linear tool calls and writes to local configuration files (CLAUDE.md/AGENTS.md); Sanitization is enforced by the evidence-only usage rule.
  • [REMOTE_CODE_EXECUTION]: The methodology contains a validated flow for uploading issue attachments using curl to PUT raw bytes to signed URLs provided by the Linear API. This is a standard and safe integration with official Linear infrastructure.
  • [COMMAND_EXECUTION]: The skill provides instructions for users to set up a scheduled health check using IDE-specific automation features (Cursor cron). This is a user-initiated, documented functional component for project monitoring rather than a hidden persistence mechanism.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 10:09 PM
Security Audit — agent-trust-hub — linear-methodology