nemoclaw-maintainer-verify-stale
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from GitHub issues. It mitigates injection risks by instructing the agent to manually reconstruct reproducer scripts rather than executing issue text directly, and requiring human review of all generated commands.
- [DYNAMIC_EXECUTION]: Reproduction scripts are generated at runtime and executed on remote Brev instances. This is controlled by environment isolation, execution timeouts, and a mandatory human approval step for every script and state change.
- [EXTERNAL_DOWNLOADS]: Downloads the NemoClaw source code from the official vendor repository and installs the "vllm" package. Security is maintained by locally verifying the SHA-256 checksum of the source archive before deployment to remote instances.
- [PRIVILEGE_ESCALATION]: Utilizes "sudo -n" for non-interactive administrative tasks, specifically for cleaning up system installation paths and performing network diagnostics. The non-interactive flag ensures the process does not wait for user credentials.
- [COMMAND_EXECUTION]: Operates various CLI tools including "brev", "docker", "git", and "gh" to provision environments, manage containers, and interface with GitHub projects.
Audit Metadata