nemoclaw-maintainer-evening

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local TypeScript scripts using Node.js to determine target versions, track progress, generate handoff summaries, and update release state. It also utilizes the GitHub CLI (gh) to list and manage labels for pull requests and issues within the NVIDIA/NemoClaw repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external GitHub pull requests and issues to generate release summaries and handoff notes. While this content originates from a trusted repository, it represents an ingestion point for data that could influence the agent's summary output. This surface is mitigated by the skill's requirement for explicit maintainer review and confirmation before taking any final release actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:19 PM
Security Audit — agent-trust-hub — nemoclaw-maintainer-evening