resolving-merge-conflicts

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The instructions direct the agent to read external, untrusted data sources such as commit messages and pull request descriptions to understand the intent behind code changes. These sources could theoretically contain adversarial content designed to influence the agent's behavior. However, this is a standard operational requirement for the task of resolving merge conflicts.
  • [COMMAND_EXECUTION]: The skill instructs the agent to discover and run the project's automated checks, such as type-checkers, test suites, and linters. This implies the execution of local shell commands based on the project's existing configuration files (e.g., package.json, requirements.txt), which is consistent with the skill's primary purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 04:26 AM
Security Audit — agent-trust-hub — resolving-merge-conflicts