nemoclaw-maintainer-cut-release-tag
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes information from external files and user inputs that could theoretically be manipulated to influence agent behavior.
- Ingestion points: Reads release-prep documents (
docs/changelog/*.mdx), plan configuration files (plan.json), evidence manifests (manifest.json), and maintainer-provided GitHub Discussion URLs. - Boundary markers: Employs strict URL pattern matching for discussions and utilizes plan hashes to ensure consistency throughout the release flow.
- Capability inventory: The skill is capable of executing
gitcommands, runningnpmscripts, and utilizing theghCLI to interact with the repository and GitHub APIs. - Sanitization: Verifies the integrity of announcement metadata (title, category, lead paragraphs, and link structures) before concluding the workflow.
- [COMMAND_EXECUTION]: The skill executes local repository scripts and standard system binaries to perform release management.
- Evidence: Orchestrates release steps via
npm run release:*commands and performs repository state checks usinggitandghCLI tools. - Evidence: The included script
release-e2e-evidence.mtsusesnode:child_process.execFileSyncto programmatically retrieve the repository HEAD SHA. - [EXTERNAL_DOWNLOADS]: Interacts with workflows hosted on a well-known third-party development service.
- Evidence: The skill dispatches events to the
brevdev/nemoclaw-imageGitHub repository to trigger and monitor production image builds during the deployment phase.
Audit Metadata