skills/udecode/dotai/linear-backlog/Gen Agent Trust Hub

linear-backlog

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface as it ingests untrusted data from external sources.
  • Ingestion points: Reads Linear issue descriptions, acceptance criteria, and linked source code (SKILL.md).
  • Boundary markers: No specific delimiters or "ignore" instructions for external ticket content are defined.
  • Capability inventory: Performs git operations (branching, merging), repository code changes, and Linear state updates (SKILL.md).
  • Sanitization: No explicit sanitization of issue content before processing is mentioned.
  • [COMMAND_EXECUTION]: The skill manages automated repository modifications and git workflow actions.
  • Autonomy: The skill is instructed to run without per-batch user confirmation to maintain workflow efficiency.
  • Safety Logic: Includes comprehensive conflict-graph construction to prevent unsafe concurrent operations (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 11:44 AM
Security Audit — agent-trust-hub — linear-backlog