skills/tjcages/linear/linear-sync/Gen Agent Trust Hub

linear-sync

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust security posture by defining a "Trust boundary" in Section 0 of METHODOLOGY.md. It explicitly warns the agent that project content (issues, comments, documents) must be treated as untrusted data, and the agent is forbidden from following any instructions embedded within that content. This is a best practice for mitigating indirect prompt injection.
  • [SAFE]: Authentication is handled correctly through official platform-provided MCP (Model Context Protocol) flows as outlined in AUTH.md. The skill does not attempt to collect, store, or transmit hardcoded credentials or API keys.
  • [SAFE]: All operations are scoped to project management within an authorized Linear workspace. No suspicious network activity, data exfiltration to unauthorized domains, or malicious command execution patterns were found.
  • [SAFE]: The skill's use of IDE-specific automation (Cursor Automations in AUTOMATION.md) follows standard documented practices for scheduled tasks and does not represent a malicious persistence mechanism.
  • [SAFE]: Analysis of the skill's instructions and methodology shows a high degree of consistency between its stated purpose (Linear project auditing) and its actual behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 12:32 AM
Security Audit — agent-trust-hub — linear-sync