resolving-merge-conflicts

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions create a surface for indirect prompt injection by processing external data from git commits, PRs, and issues. 1. Ingestion points: Git history and metadata (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Git staging and shell command execution. 4. Sanitization: Absent.
  • [COMMAND_EXECUTION]: The agent is instructed to run automated checks discovered in the project environment, leading to the execution of arbitrary shell commands defined in local configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:35 PM
Security Audit — agent-trust-hub — resolving-merge-conflicts