nemoclaw-maintainer-cut-release-tag

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes information from external files and user inputs that could theoretically be manipulated to influence agent behavior.
  • Ingestion points: Reads release-prep documents (docs/changelog/*.mdx), plan configuration files (plan.json), evidence manifests (manifest.json), and maintainer-provided GitHub Discussion URLs.
  • Boundary markers: Employs strict URL pattern matching for discussions and utilizes plan hashes to ensure consistency throughout the release flow.
  • Capability inventory: The skill is capable of executing git commands, running npm scripts, and utilizing the gh CLI to interact with the repository and GitHub APIs.
  • Sanitization: Verifies the integrity of announcement metadata (title, category, lead paragraphs, and link structures) before concluding the workflow.
  • [COMMAND_EXECUTION]: The skill executes local repository scripts and standard system binaries to perform release management.
  • Evidence: Orchestrates release steps via npm run release:* commands and performs repository state checks using git and gh CLI tools.
  • Evidence: The included script release-e2e-evidence.mts uses node:child_process.execFileSync to programmatically retrieve the repository HEAD SHA.
  • [EXTERNAL_DOWNLOADS]: Interacts with workflows hosted on a well-known third-party development service.
  • Evidence: The skill dispatches events to the brevdev/nemoclaw-image GitHub repository to trigger and monitor production image builds during the deployment phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:19 PM
Security Audit — agent-trust-hub — nemoclaw-maintainer-cut-release-tag