resolving-merge-conflicts

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process data from external sources, including commit messages, pull request descriptions, and issue trackers, which could contain malicious instructions.
  • Ingestion points: Step 2 in SKILL.md requires reading commit messages, PRs, and original issues/tickets.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present.
  • Capability inventory: Step 4 instructs the agent to discover and execute automated checks, which may include running arbitrary scripts or tests defined within the repository.
  • Sanitization: There are no instructions for sanitizing or filtering the content retrieved from these external sources before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:02 AM
Security Audit — agent-trust-hub — resolving-merge-conflicts