fix-merge-conflicts
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from git merge conflicts using
git showcommands in Phase 2. While the instructions explicitly direct the agent to treat incoming changes as untrusted, ignore instructions embedded in code or comments, and redact secret-like values, the interaction with external, potentially attacker-controlled code represents an indirect injection surface. - Ingestion points: Reads conflict sides using
git show :1:<file>,git show :2:<file>, andgit show :3:<file>inSKILL.md. - Boundary markers: The skill instructs the agent to treat incoming changes as untrusted and specifically warns against executing instructions embedded in code/comments.
- Capability inventory: Includes file system modification (editing conflicted files), command execution (
git,bun,bunx), and dependency management (bun install). - Sanitization: Instructs the agent to redact secret-like values and integrated code integrated cleanly without executing instructions.
- [COMMAND_EXECUTION]: The skill executes system commands including
git,bun, andbunxto perform repository operations, install dependencies, and run tests as part of the conflict resolution workflow. These are restricted to the tools defined in theallowed-toolsmetadata.
Audit Metadata