rebase-conflict
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to process content from external pull requests and commits, including titles, descriptions, and file versions. This presents a potential surface for indirect prompt injection, where instructions embedded within these external inputs could attempt to influence the agent's logic. The skill author has included explicit instructions for the agent to treat this content as untrusted and to ignore any embedded directives, which serves as a helpful safety measure.
- Ingestion points: Untrusted data enters the agent context through several arguments, including
args.prTitle,args.prDescription,args.prVersion,args.productionVersion, and data retrieved via theget_commit_prtool. - Boundary markers: The instructions include a 'Security' section that explicitly warns the agent to treat PR and commit content as untrusted evidence only, though the prompt does not specify the use of technical delimiters (like XML tags or unique markers) around the inputs themselves.
- Capability inventory: The skill utilizes
read_repo_fileandget_commit_prto access repository data. The primary action taken by the skill is generating resolved file content, which is then returned in a structured JSON format. - Sanitization: There is no specific requirement mentioned for the agent to sanitize or escape the content of the resolved files before returning them, which is a common pattern in documentation-focused tasks.
Audit Metadata