nemoclaw-maintainer-morning
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data retrieved from GitHub PRs and Issues.
- Ingestion points: Fetches open PRs and issues via the
ghCLI and local scripts inSKILL.md(Step 2). - Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present for handling external text.
- Capability inventory: The skill can modify repository state through
gh pr editandgh issue edit. - Sanitization: Processing is delegated to TypeScript scripts without visible sanitization or escaping in the instructions.- [COMMAND_EXECUTION]: The skill executes local scripts and system commands to manage GitHub resources.
- Executes TypeScript files using
node --experimental-strip-typeslocated at.agents/skills/nemoclaw-maintainer-day/scripts/. - Invokes the GitHub CLI (
gh) to create labels and edit PRs/issues on theNVIDIA/NemoClawrepository.
Audit Metadata