merge-artifacts

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill governs the organization and merging of internal documentation within a project's docs/ and .wip/ directories, with no requests for network access or system-level permissions.
  • [SAFE]: Conflict resolution logic requires the use of explicit <!-- CONFLICT: --> markers for subjective disagreements, ensuring that the agent does not silently override or discard conflicting data without human review.
  • [SAFE]: A mandatory decision log requirement ensures that all merge actions are recorded with a rationale, providing an audit trail for changes to the canonical artifacts.
  • [SAFE]: File operations are restricted to predictable, thread-relative paths, minimizing the risk of unauthorized file system access or path traversal.
  • [SAFE]: The instructions do not contain any prompt injection patterns, obfuscated code, or remote dependency downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 08:33 PM
Security Audit — agent-trust-hub — merge-artifacts