investigate

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of ingesting untrusted data. * Ingestion points: The skill reads data from Linear tickets, git logs, PR discussions, and MCP integrations like Datadog or Sentry. * Boundary markers: The instructions do not define delimiters or specific markers to distinguish between system instructions and data ingested from these external sources. * Capability inventory: The skill possesses capabilities to read the local filesystem, execute git commands, and write comments back to Linear tickets. * Sanitization: There is no mention of sanitizing or escaping the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 11:06 PM
Security Audit — agent-trust-hub — investigate