nemoclaw-maintainer-policies
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for an AI agent to ingest and process untrusted data (GitHub issue and pull request content) which is a common surface for indirect prompt injection.
- Ingestion points: The agent is instructed to read issue titles, bodies, and comments as evidence for classification (referenced in
references/triage-instructions.md). - Boundary markers: The policy requires the agent to base recommendations on specific evidence and provides confidence thresholds to prevent misclassification based on weak or adversarial input.
- Capability inventory: The skill primarily describes a read-only policy but anticipates writes (labels, project fields, comments) which require an "explicit authorization context" (defined in
references/workflow-policy.md). - Sanitization: The instructions mandate using dry-runs for review, setting
human_review_required: truefor security-sensitive items, and maintaining neutral language to prevent accidental confirmation of exploits.
Audit Metadata