nemoclaw-maintainer-cross-issue-sweep
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes PR descriptions, code diffs, and issue comments which are external, untrusted data sources. A malicious PR or issue could contain instructions designed to influence the agent's judgment or behavior.
- Ingestion points:
scripts/extract-fingerprint.sh(fetches PR content) andscripts/search-candidate-issues.sh(fetches issue content). - Boundary markers: The model prompt defined in
checks/relationship-judgment.mdlacks explicit delimiters or instructions to treat the interpolated{pr_body}and{issue_body}as untrusted data. - Capability inventory: The skill utilizes the
ghCLI for read-only operations (view, diff, search) within the repository. It lacks high-risk capabilities like arbitrary file writing or outbound network requests to non-whitelisted domains. - Sanitization: While the scripts use
jqto handle JSON structure, no sanitization or filtering is performed on the natural language content before it is processed by the model.
Audit Metadata