resolve-merge-conflicts

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from git branches that could contain malicious instructions aimed at subverting the agent's resolution logic. * Ingestion points: The skill reads file contents from the working tree and command output from git diff and git log in SKILL.md. * Boundary markers: Absent. The instructions do not define delimiters for code or advise the agent to ignore natural language instructions within the files. * Capability inventory: The skill can execute shell commands (npm, npx, pytest, go, git), modify local files, and commit changes to the repository. * Sanitization: None. File content is processed as-is without validation or filtering.
  • [COMMAND_EXECUTION]: The skill executes build and test commands (npm run build, npx tsc, npx jest, pytest, go test) based on the repository's configuration. This is expected behavior for verifying merge conflict resolutions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:13 AM
Security Audit — agent-trust-hub — resolve-merge-conflicts