nemoclaw-maintainer-find-review-pr

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub pull request bodies, titles, and branch names to identify linked issues and detect superseded PRs. While this presents an attack surface for indirect prompt injection, the skill only performs read operations and metadata processing without executing the content or performing dangerous operations based on that data.
  • Ingestion points: Data enters the context via gh project item-list and gh pr view outputs (PR body, title, author, branch).
  • Boundary markers: None present; the skill relies on regex patterns within the PR text.
  • Capability inventory: The skill uses gh for read-only operations (viewing PRs and projects) and jq for data processing. It does not have file-write or external network capabilities beyond the GitHub CLI.
  • Sanitization: The skill does not explicitly sanitize the text before processing, but the logic is limited to pattern matching for issue IDs.
  • [COMMAND_EXECUTION]: The skill uses the GitHub CLI (gh) and jq to fetch and process repository data. These are standard developer tools and their usage is scoped correctly to the intended maintainer workflow within the NVIDIA organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:18 PM
Security Audit — agent-trust-hub — nemoclaw-maintainer-find-review-pr