almerge
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions are limited to resolving code merge conflicts by delegating tasks to a local 'alignfirst' skill. It does not perform network operations, access sensitive credentials, or execute arbitrary remote code.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data in the form of code containing merge conflicts. While this constitutes an attack surface where malicious instructions could be embedded in code comments or conflict markers, the skill does not use unsafe interpolation or bypass standard agent safety boundaries.
Audit Metadata