nemoclaw-contributor-plan-issue
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub issues and comments, creating a potential surface for indirect prompt injection. * Ingestion points: Processes issue body and comments fetched from GitHub as described in SKILL.md. * Boundary markers: The instructions provide explicit boundaries, directing the agent to treat issue content as evidence rather than instructions that could expand authorization. * Capability inventory: The skill is capable of reading local repository files, fetching data from GitHub, and performing authorized writes like posting comments or updating labels. * Sanitization: Employs logical instructions to ignore instruction-shaped content within the retrieved issue data.
- [SAFE]: The skill performs network operations to external services to function. * Fetches issue and repository data from GitHub, which is a well-known service and central to the skill's intended purpose.
Audit Metadata