linear-tickets
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use the 'orca' CLI tool to perform actions such as moving workflow states, attaching PR/MR links, and triaging tasks.
- [INDIRECT_PROMPT_INJECTION]: The skill processes ticket text from the Linear platform, which represents an external attack surface for indirect prompt injection. The documentation acknowledges this risk by advising not to treat ticket text as instructions.
Audit Metadata