nemoclaw-maintainer-find-review-pr
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub pull request bodies, titles, and branch names to identify linked issues and detect superseded PRs. While this presents an attack surface for indirect prompt injection, the skill only performs read operations and metadata processing without executing the content or performing dangerous operations based on that data.
- Ingestion points: Data enters the context via
gh project item-listandgh pr viewoutputs (PR body, title, author, branch). - Boundary markers: None present; the skill relies on regex patterns within the PR text.
- Capability inventory: The skill uses
ghfor read-only operations (viewing PRs and projects) andjqfor data processing. It does not have file-write or external network capabilities beyond the GitHub CLI. - Sanitization: The skill does not explicitly sanitize the text before processing, but the logic is limited to pattern matching for issue IDs.
- [COMMAND_EXECUTION]: The skill uses the GitHub CLI (
gh) andjqto fetch and process repository data. These are standard developer tools and their usage is scoped correctly to the intended maintainer workflow within the NVIDIA organization.
Audit Metadata