nemoclaw-maintainer-morning

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data retrieved from GitHub PRs and Issues.
  • Ingestion points: Fetches open PRs and issues via the gh CLI and local scripts in SKILL.md (Step 2).
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present for handling external text.
  • Capability inventory: The skill can modify repository state through gh pr edit and gh issue edit.
  • Sanitization: Processing is delegated to TypeScript scripts without visible sanitization or escaping in the instructions.- [COMMAND_EXECUTION]: The skill executes local scripts and system commands to manage GitHub resources.
  • Executes TypeScript files using node --experimental-strip-types located at .agents/skills/nemoclaw-maintainer-day/scripts/.
  • Invokes the GitHub CLI (gh) to create labels and edit PRs/issues on the NVIDIA/NemoClaw repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:19 PM
Security Audit — agent-trust-hub — nemoclaw-maintainer-morning