nemoclaw-maintainer-security-code-review

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose matches the capabilities, and data flows stay within GitHub/local checkout, so this is not credential harvesting or obvious malware. The main risk is that it pulls and analyzes untrusted PR/issue content with command-capable tooling, creating moderate indirect prompt-injection and execution-surface risk for an AI agent.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
Apr 14, 2026, 11:36 PM
Package URL
pkg:socket/skills-sh/NVIDIA%2FNemoClaw%2Fnemoclaw-maintainer-security-code-review%2F@f2f0cefa4b321548490fada02c1bd4e369103ebc
Security Audit — socket — nemoclaw-maintainer-security-code-review