resolving-merge-conflicts
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the repository, including source code, commit history, and PR context, which it uses to determine how to resolve conflicts and verify changes. This creates an attack surface where malicious data could influence agent behavior.
- Ingestion points: Git conflict markers, surrounding source code, commit history, and PR context in
SKILL.md(Step 2). - Boundary markers: Absent; no specific delimiters or instructions to ignore embedded commands in the processed data are provided.
- Capability inventory: Execution of git commands and arbitrary repository-specific build, test, and regeneration scripts in
SKILL.md(Steps 4, 5, 6). - Sanitization: Absent; the skill does not specify filtering or escaping of ingested repository content.
- [DYNAMIC_EXECUTION]: The skill directs the agent to execute build, test, and file regeneration commands discovered within the target repository (Steps 4 and 5). This behavior relies on the agent executing scripts defined in potentially untrusted local configuration files.
Audit Metadata