nemoclaw-user-manage-sandboxes
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the use of
curl -fsSL ... | bashto download and execute scripts fromwww.nvidia.comandraw.githubusercontent.com/NVIDIA/. These resources are hosted on official infrastructure belonging to the skill's author (NVIDIA) and are used for legitimate setup, update, and uninstallation processes. - [COMMAND_EXECUTION]: The skill provides numerous examples of using the
nemoclawandopenshellcommand-line interfaces. These commands are necessary for the primary function of the skill, which is sandbox management, including log inspection, health checks, and container rebuilding. - [CREDENTIALS_UNSAFE]: The documentation describes how to manage service credentials (e.g., API tokens for Telegram, Discord, and Slack). It specifically notes that sensitive files like
auth.jsonare excluded from backup snapshots and that credentials are kept on the host to minimize exposure within the sandbox environment. No hardcoded secrets were detected in the files. - [DATA_EXFILTRATION]: The skill details integrations with messaging platforms like WeChat and WhatsApp. These features use official pairing flows (QR scans) and documented configuration patterns. There is no evidence of unauthorized data transmission or exfiltration behavior.
Audit Metadata