resolve-merge-conflicts
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/extract_conflict_context.pyinvokes the localgitbinary usingsubprocess.runwith secure argument lists (e.g.,git ls-files,git show). It does not enableshell=True, eliminating the risk of arbitrary shell command injection from untrusted paths or filenames. - [INDIRECT_PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface because it reads and displays raw text from unmerged repository files, which could contain adversarial instructions targeting the supervising model.
- Ingestion points: Untrusted content is ingested in
scripts/extract_conflict_context.pyviaread_text_file(reading the worktree file) andread_stage_text(reading conflict stages from the Git index). - Boundary markers: Absent. The extracted conflict hunks are rendered directly without specific structural delimiters or instructions warning the agent to ignore embedded natural language commands.
- Capability inventory: The script's capabilities are restricted to read-only operations via
subprocess.runcallinggit. There are no file-write capabilities or generic shell executors inside the script. - Sanitization: Line truncation is enforced via
truncate_linesto limit context size, but no content filtering, scrubbing, or semantic validation is applied to the text within the conflict markers.
Audit Metadata