resolving-merge-conflicts

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires the agent to execute shell commands for git operations (staging, committing, rebasing) and to run automated project checks such as typecheckers, test suites, and formatters to verify the integrity of the merge.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted content from external sources during the conflict resolution process.\n
  • Ingestion points: The agent reads conflicting code hunks, commit history, pull request descriptions, and issue tickets (SKILL.md).\n
  • Boundary markers: Absent; the instructions do not provide explicit delimiters to separate conflicting code data from instructions.\n
  • Capability inventory: Includes execution of git commands and project-specific testing/formatting tools.\n
  • Sanitization: None; the skill relies on the agent's ability to interpret external hunks and metadata without specialized filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 06:28 AM
Security Audit — agent-trust-hub — resolving-merge-conflicts