rebase-conflict

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to process content from external pull requests and commits, including titles, descriptions, and file versions. This presents a potential surface for indirect prompt injection, where instructions embedded within these external inputs could attempt to influence the agent's logic. The skill author has included explicit instructions for the agent to treat this content as untrusted and to ignore any embedded directives, which serves as a helpful safety measure.
  • Ingestion points: Untrusted data enters the agent context through several arguments, including args.prTitle, args.prDescription, args.prVersion, args.productionVersion, and data retrieved via the get_commit_pr tool.
  • Boundary markers: The instructions include a 'Security' section that explicitly warns the agent to treat PR and commit content as untrusted evidence only, though the prompt does not specify the use of technical delimiters (like XML tags or unique markers) around the inputs themselves.
  • Capability inventory: The skill utilizes read_repo_file and get_commit_pr to access repository data. The primary action taken by the skill is generating resolved file content, which is then returned in a structured JSON format.
  • Sanitization: There is no specific requirement mentioned for the agent to sanitize or escape the content of the resolved files before returning them, which is a common pattern in documentation-focused tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:03 PM
Security Audit — agent-trust-hub — rebase-conflict