conflict-resolver

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze untrusted code snippets containing Git conflict markers. This represents an indirect prompt injection surface where instructions hidden within code could attempt to influence the agent's resolution logic.
  • Ingestion points: Source code files analyzed during conflict identification steps.
  • Boundary markers: The skill does not explicitly define delimiters to separate untrusted code content from the agent's internal instructions.
  • Capability inventory: The skill suggests command execution (e.g., git checkout, git add) and provides templates for local shell scripts.
  • Sanitization: No explicit sanitization or filtering of the processed code content is mentioned.
  • [SAFE]: The core instructions define a helpful expert persona and do not attempt to override safety filters, bypass constraints, or extract system prompts.
  • [SAFE]: The provided shell scripts (auto-resolve.sh and verify-resolution.sh) and command examples use standard local Git operations and project scripts (npm). There are no network exfiltration patterns, hardcoded credentials, or remote code downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:05 AM
Security Audit — agent-trust-hub — conflict-resolver