linear

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a documentation resource (SKILL.md) and metadata file (metadata.json) provided by a known vendor (Apideck). It teaches the agent how to interact with the Linear service through a unified API.
  • [DATA_EXFILTRATION]: The skill demonstrates network operations using the Apideck SDK and the Proxy API (unify.apideck.com). These operations are targeted at the vendor's official infrastructure and are used for their intended purpose of issue tracking. No unauthorized data exfiltration or sensitive file access is present.
  • [CREDENTIALS_UNSAFE]: The skill uses best practices for secret management. Code examples use environment variables (process.env.APIDECK_API_KEY) and placeholders (your-consumer-id) rather than hardcoding sensitive credentials.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns or untrusted dependency installations were detected. The skill references standard vendor-provided packages like '@apideck/unify'.
  • [INDIRECT_PROMPT_INJECTION]: While the skill enables the agent to read and process data from an external source (Linear tickets), which is an indirect prompt injection surface, this is inherent to the integration's primary function. There are no instructions to bypass safety filters or execute malicious commands based on the external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 11:01 AM
Security Audit — agent-trust-hub — linear