linear-backlog
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface as it ingests untrusted data from external sources.
- Ingestion points: Reads Linear issue descriptions, acceptance criteria, and linked source code (SKILL.md).
- Boundary markers: No specific delimiters or "ignore" instructions for external ticket content are defined.
- Capability inventory: Performs git operations (branching, merging), repository code changes, and Linear state updates (SKILL.md).
- Sanitization: No explicit sanitization of issue content before processing is mentioned.
- [COMMAND_EXECUTION]: The skill manages automated repository modifications and git workflow actions.
- Autonomy: The skill is instructed to run without per-batch user confirmation to maintain workflow efficiency.
- Safety Logic: Includes comprehensive conflict-graph construction to prevent unsafe concurrent operations (SKILL.md).
Audit Metadata