nemoclaw-maintainer-classify-ci-failure
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process untrusted data from GitHub Actions logs and artifact contents, creating a surface for injection.
- Ingestion points: External data enters the system through
gh apicalls to fetch CI job logs (/logs) and ZIP-compressed artifacts (/zip). - Boundary markers: The skill does not employ specific delimiters or instruction-bypass warnings when presenting the processed log output to the AI agent.
- Capability inventory: The skill possesses the ability to execute shell commands (
bash,gh, coreutils) and perform file system operations (creation, read, and recursive removal) within process-owned temporary directories. - Sanitization: The script implements a detailed
redact()function using regular expressions to strip credentials (e.g., AWS keys, GitHub tokens, Bearer tokens) and usesprojectText()to enforce character, line, and total byte limits on all data returned to the agent. - [COMMAND_EXECUTION]: The skill invokes system binaries and the GitHub CLI to perform its analysis.
- Evidence: The
executefunction inscripts/classify-ci-failure.mtsusesnode:child_process.spawnto run a Node.js wrapper that manages process groups and invokesbash -cor direct executable paths. - Mitigation: The script performs extensive validation of the
ghexecutable path, ensuring it resides in standard locations (/usr/bin,/usr/local/bin, or$HOME/.local/bin), is not a symbolic link, is owned by root or the current user, and is not world-writable. Shell commands executed viabash -care escaped using a custom single-quote replacement function to prevent argument injection.
Audit Metadata