nemoclaw-maintainer-analyze-pr-value-stream

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes system commands including gh, unzip, zipinfo, and node via the execFile API. All user-supplied parameters, such as repository names and pull request numbers, are validated against strict regular expressions or sanitized before being passed as arguments in the command array to prevent shell injection.
  • [EXTERNAL_DOWNLOADS]: The analyzer fetches pull request metadata, workflow logs, and test artifacts from GitHub. These downloads are performed using the authenticated gh CLI and are restricted to the repository context configured for the skill.
  • [DYNAMIC_EXECUTION]: The script dynamically generates a temporary JavaScript file used as a Vitest reporter to merge test results. This file is executed using the local Node.js runtime. The generated code follows a static template and does not incorporate unsanitized external input into the executable logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data that could contain malicious instructions designed to influence the agent.
  • Ingestion points: Pull request comments, review text, and timeline events are fetched from the GitHub API in analyze-pr-value-stream.mts and export-pr-lifetime-trace.mts.
  • Boundary markers: Collected data is structured within a JSON report; however, no specific delimiters or "ignore embedded instructions" warnings are applied to the text fields before they are presented to the agent.
  • Capability inventory: The skill possesses capabilities to execute shell commands, run Node.js processes, and perform filesystem operations within the working directory.
  • Sanitization: Diagnostic messages are redacted to remove tokens and secrets, and repository names are regex-validated, but the text content of PR comments is ingested as raw strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:19 PM
Security Audit — agent-trust-hub — nemoclaw-maintainer-analyze-pr-value-stream