nemoclaw-maintainer-normalize-title-tags
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
ghCLI tool to verify GitHub authentication and perform repository maintenance operations via the GitHub API. - [COMMAND_EXECUTION]: A local TypeScript script (
normalize-title-tags.ts) is executed using the Node.js runtime to process and update issue metadata. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from GitHub issue and pull request titles within the targeted repository.
- Ingestion points: The
listItemsfunction inscripts/normalize-title-tags.tsfetches titles from the GitHub API usinggh api. - Boundary markers: None; titles are processed directly for cleanup logic.
- Capability inventory: The script has the capability to update issue titles using
gh api -X PATCH. - Sanitization: Shell command injection is prevented by using
execFileSyncwith argument arrays, ensuring that external title content is treated as data rather than executable shell input.
Audit Metadata