nemoclaw-maintainer-policies

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill package is restricted to documentation and policy reference files. No executable scripts, binaries, or shell commands are included in the package.
  • [SAFE]: The triage instructions for AI agents explicitly mandate safety controls for processing external data, such as requiring human-in-the-loop review for high-risk actions and operating in a recommendation-only mode by default.
  • [SAFE]: While the skill provides instructions for an agent to interact with untrusted GitHub issue and PR data (Indirect Prompt Injection surface), it enforces strict sanitization policies, including confidence thresholds and rationale requirements to prevent accidental obedience to embedded instructions.
  • [SAFE]: External references are limited to legitimate project resources associated with the verified author (NVIDIA/NemoClaw), and no obfuscation or suspicious redirection techniques were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 12:36 AM
Security Audit — agent-trust-hub — nemoclaw-maintainer-policies