nemoclaw-maintainer-pr-comparator
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes multiple shell scripts to automate repository maintenance tasks. These include
find-candidates.shfor PR discovery,collect-gates.shfor status check aggregation,check-coderabbit-threads.shfor review thread resolution via GitHub GraphQL, andparse-supersession.shfor identifying related PRs. - [DYNAMIC_EXECUTION]: Step 4 of the workflow executes a shell script directly from the repository's git history using
bash <(git show origin/main:...). This is used to run project-specific gate checks from the canonical branch of the checkout. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub issue descriptions, comments, and pull request bodies to determine merge eligibility.
- Ingestion points: Content is fetched using
gh issue viewandgh pr viewwithinSKILL.mdand several helper scripts. - Boundary markers: The skill does not explicitly define delimiters for external text, but requires the evaluator to provide specific reasoning evidence, including file and line references, for every judgment to ensure traceability.
- Capability inventory: The agent utilizes
bash,python,git, andghto read and evaluate repository state. - Sanitization: The skill relies on structured evaluation tiers (0, 1, 2) and mandatory human review of the generated scorecard before any merge action is recommended.
Audit Metadata