nemoclaw-maintainer-normalize-title-tags

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the gh CLI tool to verify GitHub authentication and perform repository maintenance operations via the GitHub API.
  • [COMMAND_EXECUTION]: A local TypeScript script (normalize-title-tags.ts) is executed using the Node.js runtime to process and update issue metadata.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub issue and pull request titles within the targeted repository.
  • Ingestion points: The listItems function in scripts/normalize-title-tags.ts fetches titles from the GitHub API using gh api.
  • Boundary markers: None; titles are processed directly for cleanup logic.
  • Capability inventory: The script has the capability to update issue titles using gh api -X PATCH.
  • Sanitization: Shell command injection is prevented by using execFileSync with argument arrays, ensuring that external title content is treated as data rather than executable shell input.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:18 PM
Security Audit — agent-trust-hub — nemoclaw-maintainer-normalize-title-tags