nemoclaw-user-deploy-remote

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill details several administrative shell commands for provisioning instances and managing the NemoClaw environment. These commands are consistent with the intended use case of remote deployment and management.\n- [EXTERNAL_DOWNLOADS]: Resources and provisioning services are accessed from vendor-controlled domains (brev.nvidia.com). These downloads are part of the standard installation and update process for the NemoClaw toolset.\n- [PROMPT_INJECTION]: The skill documents the setup of messaging channels (Telegram), which represents a surface for indirect prompt injection. Ingestion points: Telegram API messages processed by the agent (SKILL.md). Boundary markers: Instructions for implementing user allowlists and pairing mechanisms. Capability inventory: Commands and scripts are executed within a hardened sandbox with dropped capabilities and Landlock-enforced read-only paths (references/sandbox-hardening.md). Sanitization: Relies on platform-level controls and documented user-configured allowlists.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 11:35 PM
Security Audit — agent-trust-hub — nemoclaw-user-deploy-remote