investigate
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of ingesting untrusted data. * Ingestion points: The skill reads data from Linear tickets, git logs, PR discussions, and MCP integrations like Datadog or Sentry. * Boundary markers: The instructions do not define delimiters or specific markers to distinguish between system instructions and data ingested from these external sources. * Capability inventory: The skill possesses capabilities to read the local filesystem, execute git commands, and write comments back to Linear tickets. * Sanitization: There is no mention of sanitizing or escaping the content retrieved from external sources before it is processed by the agent.
Audit Metadata