resolving-merge-conflicts
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions create a surface for indirect prompt injection by processing external data from git commits, PRs, and issues. 1. Ingestion points: Git history and metadata (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Git staging and shell command execution. 4. Sanitization: Absent.
- [COMMAND_EXECUTION]: The agent is instructed to run automated checks discovered in the project environment, leading to the execution of arbitrary shell commands defined in local configuration files.
Audit Metadata