nemoclaw-maintainer-cross-issue-sweep

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes PR descriptions, code diffs, and issue comments which are external, untrusted data sources. A malicious PR or issue could contain instructions designed to influence the agent's judgment or behavior.
  • Ingestion points: scripts/extract-fingerprint.sh (fetches PR content) and scripts/search-candidate-issues.sh (fetches issue content).
  • Boundary markers: The model prompt defined in checks/relationship-judgment.md lacks explicit delimiters or instructions to treat the interpolated {pr_body} and {issue_body} as untrusted data.
  • Capability inventory: The skill utilizes the gh CLI for read-only operations (view, diff, search) within the repository. It lacks high-risk capabilities like arbitrary file writing or outbound network requests to non-whitelisted domains.
  • Sanitization: While the scripts use jq to handle JSON structure, no sanitization or filtering is performed on the natural language content before it is processed by the model.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:19 PM
Security Audit — agent-trust-hub — nemoclaw-maintainer-cross-issue-sweep