fix-merge-conflicts
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of file content containing git conflict markers.
- Ingestion points: The workflow involves reading all conflicting files from the local environment as described in SKILL.md.
- Boundary markers: There are no explicit instructions or delimiters to prevent the agent from interpreting instructions embedded within the conflict markers as its own.
- Capability inventory: The skill possesses the ability to execute shell commands via compile, lint, and tests tasks, as well as modify the repository state using git stage.
- Sanitization: The skill lacks validation or sanitization mechanisms to filter malicious instructions contained within the code being resolved.
- [COMMAND_EXECUTION]: The skill executes various development tools during its workflow.
- Evidence: The instructions explicitly direct the agent to run compile, lint, and relevant tests (step 5) and to regenerate lockfiles using local package manager tools (step 4).
Audit Metadata