nemoclaw-maintainer-classify-ci-failure

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process untrusted data from GitHub Actions logs and artifact contents, creating a surface for injection.
  • Ingestion points: External data enters the system through gh api calls to fetch CI job logs (/logs) and ZIP-compressed artifacts (/zip).
  • Boundary markers: The skill does not employ specific delimiters or instruction-bypass warnings when presenting the processed log output to the AI agent.
  • Capability inventory: The skill possesses the ability to execute shell commands (bash, gh, coreutils) and perform file system operations (creation, read, and recursive removal) within process-owned temporary directories.
  • Sanitization: The script implements a detailed redact() function using regular expressions to strip credentials (e.g., AWS keys, GitHub tokens, Bearer tokens) and uses projectText() to enforce character, line, and total byte limits on all data returned to the agent.
  • [COMMAND_EXECUTION]: The skill invokes system binaries and the GitHub CLI to perform its analysis.
  • Evidence: The execute function in scripts/classify-ci-failure.mts uses node:child_process.spawn to run a Node.js wrapper that manages process groups and invokes bash -c or direct executable paths.
  • Mitigation: The script performs extensive validation of the gh executable path, ensuring it resides in standard locations (/usr/bin, /usr/local/bin, or $HOME/.local/bin), is not a symbolic link, is owned by root or the current user, and is not world-writable. Shell commands executed via bash -c are escaped using a custom single-quote replacement function to prevent argument injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 05:17 PM
Security Audit — agent-trust-hub — nemoclaw-maintainer-classify-ci-failure