nemoclaw-user-manage-sandboxes

Pass

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of curl -fsSL ... | bash to download and execute scripts from www.nvidia.com and raw.githubusercontent.com/NVIDIA/. These resources are hosted on official infrastructure belonging to the skill's author (NVIDIA) and are used for legitimate setup, update, and uninstallation processes.
  • [COMMAND_EXECUTION]: The skill provides numerous examples of using the nemoclaw and openshell command-line interfaces. These commands are necessary for the primary function of the skill, which is sandbox management, including log inspection, health checks, and container rebuilding.
  • [CREDENTIALS_UNSAFE]: The documentation describes how to manage service credentials (e.g., API tokens for Telegram, Discord, and Slack). It specifically notes that sensitive files like auth.json are excluded from backup snapshots and that credentials are kept on the host to minimize exposure within the sandbox environment. No hardcoded secrets were detected in the files.
  • [DATA_EXFILTRATION]: The skill details integrations with messaging platforms like WeChat and WhatsApp. These features use official pairing flows (QR scans) and documented configuration patterns. There is no evidence of unauthorized data transmission or exfiltration behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 12, 2026, 07:42 PM
Security Audit — agent-trust-hub — nemoclaw-user-manage-sandboxes