nemoclaw-community-maintainer-policies
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of documentation (Markdown and JSON) defining repository management policies. No executable files, scripts, or binaries are included in the package.\n- [SAFE]: All references point to local documentation files within the skill directory. There are no external downloads or remote script executions.\n- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process content from GitHub issues and pull requests, which is an ingestion point for untrusted data. However, the skill provides strong defensive guidelines to mitigate this risk.\n
- Ingestion points: GitHub issue and pull request titles, bodies, and associated metadata.\n
- Boundary markers: None specified for external content.\n
- Capability inventory: The agent is guided to perform triage tasks, which typically require GitHub API tools for labeling and metadata updates.\n
- Sanitization: The policy mandates that the agent perform dry-runs and obtain explicit user authorization before making any metadata changes, and it explicitly forbids the public disclosure of security vulnerabilities.
Audit Metadata