resolving-merge-conflicts
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection by instructing the agent to process data from external repository sources.\n- Ingestion points: The agent is directed to read commit messages, PR descriptions, and issue contents to determine original developer intent (SKILL.md).\n- Boundary markers: No explicit delimiters or boundary markers are defined to isolate untrusted external content from the agent's instructions.\n- Capability inventory: The skill is granted Bash, Write, Edit, and Read capabilities (SKILL.md), allowing for file modification and command execution based on interpreted external data.\n- Sanitization: The skill lacks procedures for sanitizing or validating external repository metadata before processing.
Audit Metadata