resolving-merge-conflicts

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external content such as git conflict hunks, commit messages, PR descriptions, and issue trackers. This data could include malicious instructions intended to influence the agent's logic or the commands it executes.
  • Ingestion points: Conflict markers, hunks, commit messages, PR details, and issue trackers (SKILL.md).
  • Capability inventory: Identifying and running shell commands for static analysis, tests, and code formatting (SKILL.md).
  • Boundary markers: Not present.
  • Sanitization: Not present.
  • [COMMAND_EXECUTION]: The skill instructs the agent to discover and run automated checks (such as Larastan, Pest, or Pint) within the project's environment, which involves executing shell commands based on project configuration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 12:39 AM
Security Audit — agent-trust-hub — resolving-merge-conflicts