nemoclaw-maintainer-release-notes
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from GitHub PR descriptions and usernames, which could theoretically contain malicious instructions.
- Ingestion points: Data is ingested from GitHub PR bodies, titles, and author usernames via the
ghandgitcommands inSKILL.md(Steps 2 and 5). - Boundary markers: No explicit delimiters are used to wrap the untrusted PR content when processed by the agent.
- Capability inventory: The skill possesses the capability to execute shell commands (
git,gh) and write to the local file system (release-note-draft.md). - Sanitization: The skill relies on the agent to synthesize summaries rather than directly executing content. More importantly, the primary output is a local draft meant for manual human review and posting, which serves as a critical safety checkpoint before any external communication occurs.
- [COMMAND_EXECUTION]: The skill uses standard developer tools (
gitandgh) to interact with the project repository. These operations are scoped to theNVIDIA/NemoClawrepository and are consistent with the skill's stated purpose of release maintenance.
Audit Metadata