resolving-merge-conflicts
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to ingest and analyze untrusted external data to understand the intent behind code changes.
- Ingestion points: SKILL.md (Step 2) instructs the agent to read git history, conflicting files, commit messages, pull request descriptions, and issue tickets.
- Boundary markers: No specific delimiters or instructions are provided to help the agent distinguish between legitimate documentation and potentially malicious instructions embedded in git metadata.
- Capability inventory: The agent has the capability to execute shell commands for git operations and run automated project checks (SKILL.md, Step 4).
- Sanitization: There is no mention of sanitizing or filtering the content read from git logs or PR descriptions.
- Analysis: An attacker could craft a malicious commit message or PR description that includes hidden instructions designed to trick the agent into performing unauthorized actions during the resolution process.
- [COMMAND_EXECUTION]: The skill requires the agent to run project-specific automated checks.
- Evidence: SKILL.md (Step 4) instructs the agent to "Discover the project's automated checks and run them, typically typecheck, then tests, then format."
- Analysis: This capability is standard for a developer agent, but it presents a risk if the agent is operating on an untrusted repository. A malicious actor could configure the project's test suite to execute harmful commands when the agent attempts to run the expected "automated checks."
Audit Metadata