linear-setup
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill requires the use of official Linear MCP servers and platform-native OAuth authentication, explicitly instructing agents not to use unofficial wrappers or hardcode credentials.
- [PROMPT_INJECTION]: While the skill processes untrusted project data such as Linear issues and repository files, it includes a dedicated 'Trust Boundary' section in METHODOLOGY.md. This section provides specific directives to treat external content as data rather than instructions, mitigating potential indirect prompt injection attacks.
- [COMMAND_EXECUTION]: The skill methodology includes a procedure for uploading attachments using curl to interact with Linear's signed URLs. This is a legitimate functional requirement for project tracking and is conducted via a validated process.
- [SAFE]: The automation configuration described for Cursor utilizes intended platform features for scheduled health checks and requires explicit user setup and verification.
Audit Metadata