resolving-merge-conflicts

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to discover and run the repository's automated checks, including type-checkers, tests, and formatters. This is standard behavior for a developer-oriented skill to ensure code integrity after a merge.
  • [DATA_EXPOSURE]: The agent is directed to read commit messages, Pull Request descriptions, and issue tickets. This is necessary context for understanding the original intent of conflicting changes.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it processes untrusted data from external sources (PR descriptions and issue comments) which could theoretically contain malicious instructions. However, this risk is inherent to the task of software development and is not an indicator of a malicious skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 07:18 AM
Security Audit — agent-trust-hub — resolving-merge-conflicts