nemoclaw-maintainer-audit-e2e-assertions
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process potentially untrusted external data, such as failure logs and source code, which could contain instructions meant to influence the agent. The instructions lack clear boundary delimiters to separate this data from the agent's core instructions.\n
- Ingestion points: Test failure logs, CI artifact identities, and repository source code (SKILL.md).\n
- Boundary markers: No specific delimiters or markers are defined to isolate external data strings from the execution prompt.\n
- Capability inventory: The skill is authorized to perform source code modifications and initiate E2E execution workflows (SKILL.md).\n
- Sanitization: The instructions mention redacting secrets but do not provide for escaping or filtering of the content being analyzed.\n- [COMMAND_EXECUTION]: The instructions require the agent to modify the codebase and trigger environment-level workflows to validate fixes.\n
- Evidence: The skill directs the agent to "Batch the Supported Repairs" and "Use the repository E2E execution workflow" (SKILL.md).
Audit Metadata