nemoclaw-maintainer-day
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local TypeScript scripts and external CLI tools like
gitandghto automate repository tasks. These commands are invoked usingexecFileSyncinscripts/shared.ts, which safely passes arguments as a discrete array, effectively mitigating shell injection risks. - [SAFE]: The skill manages its own local state in a
.nemoclaw-maintainerdirectory. It includes logic to automatically add this directory to.git/info/exclude, ensuring that local agent metadata is not accidentally committed to the repository. - [SAFE]: No hardcoded credentials or sensitive data exfiltration patterns were detected. All network communication is performed through established development tools (git, gh) targeting the project's official repository infrastructure.
- [SAFE]: The skill's architecture relies on Node.js's built-in capability to run TypeScript files directly (
--experimental-strip-types), avoiding the need for external build dependencies or unverifiable remote script execution.
Audit Metadata