fix-merge-conflicts

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from git merge conflicts using git show commands in Phase 2. While the instructions explicitly direct the agent to treat incoming changes as untrusted, ignore instructions embedded in code or comments, and redact secret-like values, the interaction with external, potentially attacker-controlled code represents an indirect injection surface.
  • Ingestion points: Reads conflict sides using git show :1:<file>, git show :2:<file>, and git show :3:<file> in SKILL.md.
  • Boundary markers: The skill instructs the agent to treat incoming changes as untrusted and specifically warns against executing instructions embedded in code/comments.
  • Capability inventory: Includes file system modification (editing conflicted files), command execution (git, bun, bunx), and dependency management (bun install).
  • Sanitization: Instructs the agent to redact secret-like values and integrated code integrated cleanly without executing instructions.
  • [COMMAND_EXECUTION]: The skill executes system commands including git, bun, and bunx to perform repository operations, install dependencies, and run tests as part of the conflict resolution workflow. These are restricted to the tools defined in the allowed-tools metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 08:30 AM
Security Audit — agent-trust-hub — fix-merge-conflicts