nemoclaw-maintainer-triage
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (
gh) to perform read and write operations on theNVIDIA/NemoClawrepository. It executes commands such asgh issue view,gh pr view,gh issue list, andgh pr listto fetch data, and subsequently performs write operations to update labels, project fields, and post comments after user confirmation. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, creating an attack surface where maliciously crafted issue or PR content could attempt to influence the agent's triaging decisions.
- Ingestion points: The skill ingests issue and pull request metadata, including titles, bodies, and author information, via GitHub CLI output as described in Step 2.
- Boundary markers: The instructions do not specify the use of clear delimiters or boundary markers to isolate untrusted user content from the agent's internal reasoning logic.
- Capability inventory: The skill is capable of modifying the state of the GitHub repository, including setting native Issue Types, updating Project fields (Priority and Status), and posting public comments (Step 4).
- Sanitization: No automated sanitization or filtering of external content is mentioned; however, the skill implements a strict human-in-the-loop (HITL) control in Steps 3 and 4, requiring a maintainer to explicitly accept a 'dry run' proposal before any changes are executed.
Audit Metadata