nemoclaw-maintainer-day
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local system tools including
git,gh(GitHub CLI), andnpmvia theexecFileSyncAPI to manage repository state and pull request workflows. These operations are restricted to the project repository and follow secure patterns for argument handling by using an argument array rather than shell interpolation. - [DYNAMIC_EXECUTION]: The skill uses
nodewith the--experimental-strip-typesflag to execute its own internal TypeScript maintenance scripts located in the.agents/skills/nemoclaw-maintainer-day/scripts/directory. This is a standard mechanism for running local automation logic without external dependency downloads. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data including pull request titles, bodies, and review comments, which constitutes a potential surface for indirect prompt injection.
- Ingestion points: External content is ingested in
scripts/triage.ts,scripts/check-gates.ts, andSALVAGE-PR.mdthrough GitHub API calls. - Boundary markers: The skill does not implement specific delimiters for natural language content processing.
- Capability inventory: The skill has significant capabilities including performing
git pushoperations, approving pull requests, and executing local test suites vianpm test. - Sanitization: Content is parsed as JSON but not specifically sanitized for instruction-like patterns.
- Mitigation: The skill mitigates this risk by implementing deterministic hard gates in
scripts/check-gates.ts, such as requiring DCO compliance, verified commit signatures, and specific GitHub App authorization (App ID 15368) before any pull request can be approved.
Audit Metadata