nemoclaw-maintainer-day

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local system tools including git, gh (GitHub CLI), and npm via the execFileSync API to manage repository state and pull request workflows. These operations are restricted to the project repository and follow secure patterns for argument handling by using an argument array rather than shell interpolation.
  • [DYNAMIC_EXECUTION]: The skill uses node with the --experimental-strip-types flag to execute its own internal TypeScript maintenance scripts located in the .agents/skills/nemoclaw-maintainer-day/scripts/ directory. This is a standard mechanism for running local automation logic without external dependency downloads.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data including pull request titles, bodies, and review comments, which constitutes a potential surface for indirect prompt injection.
  • Ingestion points: External content is ingested in scripts/triage.ts, scripts/check-gates.ts, and SALVAGE-PR.md through GitHub API calls.
  • Boundary markers: The skill does not implement specific delimiters for natural language content processing.
  • Capability inventory: The skill has significant capabilities including performing git push operations, approving pull requests, and executing local test suites via npm test.
  • Sanitization: Content is parsed as JSON but not specifically sanitized for instruction-like patterns.
  • Mitigation: The skill mitigates this risk by implementing deterministic hard gates in scripts/check-gates.ts, such as requiring DCO compliance, verified commit signatures, and specific GitHub App authorization (App ID 15368) before any pull request can be approved.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:19 PM
Security Audit — agent-trust-hub — nemoclaw-maintainer-day