linear-discipline

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [TRUST_BOUNDARY]: The skill explicitly defines a trust boundary in METHODOLOGY.md (§0), instructing the agent to treat all Linear issues, comments, and repository files as untrusted data. It mandates ignoring instructions embedded in such content (e.g., requests to reveal secrets or run commands) and using them only as evidence for tracking decisions.
  • [SAFE_CREDENTIAL_MANAGEMENT]: The AUTH.md file correctly instructs users to set up authentication via official platform-specific MCP settings (Cursor, Claude Code) rather than asking for API keys directly. It specifically warns the agent never to invent unofficial API wrappers or curl commands for authentication.
  • [PRIVILEGE_MINIMIZATION]: The skill enforces a 'search before create' policy and requires explicit user consent before making any write operations to existing projects, preventing unauthorized modifications to user workflows.
  • [NO_REMOTE_CODE]: The skill relies entirely on the local environment and the official Linear MCP server. There are no patterns of downloading or executing external scripts.
  • [INDIRECT_PROMPT_INJECTION_DEFENSE]: While the skill processes project data which could theoretically contain injections, it implements a mandatory evidence chain and defensive markers (as described in the Trust Boundary section) to mitigate this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 09:25 PM
Security Audit — agent-trust-hub — linear-discipline