Verdaccio Code Review
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
Perform a requested security review of a NemoClaw PR or a PR linked to an issue.
$ npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install NVIDIA/NemoClaw nemoclaw-maintainer-security-code-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/NVIDIA/NemoClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nemoclaw-maintainer-security-code-review .claude/skills/nemoclaw-maintainer-security-code-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "nemoclaw-maintainer-security-code-review" agent skill from https://github.com/NVIDIA/NemoClaw/tree/main/.agents/skills/nemoclaw-maintainer-security-code-review into .claude/skills/nemoclaw-maintainer-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nemoclaw-maintainer-security-code-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/NVIDIA/NemoClaw/tree/main/.agents/skills/nemoclaw-maintainer-security-code-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install NVIDIA/NemoClaw nemoclaw-maintainer-security-code-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NVIDIA/NemoClaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/nemoclaw-maintainer-security-code-review .agents/skills/nemoclaw-maintainer-security-code-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "nemoclaw-maintainer-security-code-review" agent skill from https://github.com/NVIDIA/NemoClaw/tree/main/.agents/skills/nemoclaw-maintainer-security-code-review into .agents/skills/nemoclaw-maintainer-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nemoclaw-maintainer-security-code-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install NVIDIA/NemoClaw nemoclaw-maintainer-security-code-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NVIDIA/NemoClaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/nemoclaw-maintainer-security-code-review .cursor/skills/nemoclaw-maintainer-security-code-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "nemoclaw-maintainer-security-code-review" agent skill from https://github.com/NVIDIA/NemoClaw/tree/main/.agents/skills/nemoclaw-maintainer-security-code-review into .cursor/skills/nemoclaw-maintainer-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nemoclaw-maintainer-security-code-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/NVIDIA/NemoClaw.git --path .agents/skills/nemoclaw-maintainer-security-code-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install NVIDIA/NemoClaw nemoclaw-maintainer-security-code-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NVIDIA/NemoClaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/nemoclaw-maintainer-security-code-review .gemini/skills/nemoclaw-maintainer-security-code-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "nemoclaw-maintainer-security-code-review" agent skill from https://github.com/NVIDIA/NemoClaw/tree/main/.agents/skills/nemoclaw-maintainer-security-code-review into .gemini/skills/nemoclaw-maintainer-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nemoclaw-maintainer-security-code-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install NVIDIA/NemoClaw nemoclaw-maintainer-security-code-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/NVIDIA/NemoClaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/nemoclaw-maintainer-security-code-review .github/skills/nemoclaw-maintainer-security-code-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "nemoclaw-maintainer-security-code-review" agent skill from https://github.com/NVIDIA/NemoClaw/tree/main/.agents/skills/nemoclaw-maintainer-security-code-review into .github/skills/nemoclaw-maintainer-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nemoclaw-maintainer-security-code-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install NVIDIA/NemoClaw nemoclaw-maintainer-security-code-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/NVIDIA/NemoClaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/nemoclaw-maintainer-security-code-review .opencode/skills/nemoclaw-maintainer-security-code-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "nemoclaw-maintainer-security-code-review" agent skill from https://github.com/NVIDIA/NemoClaw/tree/main/.agents/skills/nemoclaw-maintainer-security-code-review into .opencode/skills/nemoclaw-maintainer-security-code-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "nemoclaw-maintainer-security-code-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
nemoclaw-maintainer-security-code-reviewPerform a requested security review of a NemoClaw PR or a PR linked to an issue.
Nemoclaw Maintainer Security Code Review is an agent skill from NVIDIA/NemoClaw, published by the product's own GitHub organization. Perform a requested security review of a NemoClaw PR or a PR linked to an issue. Use for vulnerability or trust-boundary assessment.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Code review and Security review. It works with GitHub. The repository describes itself as: Run agents like Hermes, LangChain Deep Agents, and OpenClaw more securely inside NVIDIA OpenShell with managed inference. The licence is Apache-2.0.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit fcbbab0. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
ghgitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Nemoclaw Maintainer Security Code Review loads about 1.1k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 505 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from NVIDIA/NemoClaw at commit fcbbab0, republished under its Apache-2.0 licence (© NVIDIA). 505 words, ~1,100 tokens.
.claude/skills/nemoclaw-maintainer-security-code-review/SKILL.md (or your agent's skills folder).<!-- SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -->
<!-- SPDX-License-Identifier: Apache-2.0 -->
Review the changes in a GitHub PR for security. An issue input must identify one open linked PR. Report a verdict for each category.
gh (GitHub CLI) must be installed and authenticated.git must be available.If the user gives a PR or issue URL, extract the owner, repository, and number. Otherwise, ask for the URL.
Supported URL formats:
https://github.com/OWNER/REPO/pull/NUMBERhttps://github.com/OWNER/REPO/issues/NUMBERFor a PR URL, verify the number before Step 2:
gh pr view <number> --repo OWNER/REPO --json number,urlFor an issue URL, list its open closing PRs:
gh issue view <number> --repo OWNER/REPO --json closedByPullRequestsReferences \
--jq '.closedByPullRequestsReferences | map(select(.state == "OPEN")) | .[].number'Continue only when this returns one PR number, and verify that number with gh pr view.
If it returns zero or more than one, stop and ask for the PR URL.
Use the verified PR number in each later command.
Compare gh repo view --json nameWithOwner -q .nameWithOwner with the URL.
If the repositories match, check out the verified PR:
gh pr checkout <number>If the repositories do not match, clone the target to a temporary directory:
REVIEW_DIR=$(mktemp -d)
gh repo clone OWNER/REPO "$REVIEW_DIR"
cd "$REVIEW_DIR"
gh pr checkout <number>List all files changed from the base branch:
git diff main...HEAD --name-statusIf the PR targets another branch, use that branch as the base. Check it with:
gh pr view <number> --json baseRefName -q .baseRefNameRead each changed file. Read its diff:
git diff main...HEAD -- <file>If a PR changes more than 30 files, review them in this order:
Read the canonical Security Rubric. Independently evaluate the completed change against every category, including its trust-boundary questions and expected evidence. Do not rely on planning or implementation conclusions as review evidence.
For each of the nine categories, assign a verdict:
Structure the output as follows:
One paragraph summarizing the risk and whether the PR is safe to merge.
One row per finding:
| # | Category | Severity | File:Line | Description | Recommendation |
|---|
If there are no findings, state that the review found none.
For each category, give its PASS, WARNING, or FAIL verdict and reason.
List every file analyzed.
© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .agents/skills/nemoclaw-maintainer-security-code-review of NVIDIA/NemoClaw.
Open the folder on GitHubat commit fcbbab0
Nemoclaw Maintainer Security Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Nemoclaw Maintainer Security Code Review this skillNVIDIA/NemoClaw | 23k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Verdaccio Code Reviewverdaccio/verdaccio | 18k | — | ~853 | Automated safety check: Pass | MIT | |
| Requesting Code ReviewHezaoHezao/poirot | 249 | 5 repos | ~1.6k | Automated safety check: Pass | MIT | |
| Code Reviewcoderabbitai/skills | 187 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Vibers Code Reviewsickn33/agentic-awesome-skills | 47k | 2 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Code Review Specialistluongnv89/claude-howto | 42k | — | ~764 | Automated safety check: Pass | MIT |
verdaccio/verdaccio
Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.
HezaoHezao/poirot
Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.
coderabbitai/skills
Run CodeRabbit CLI reviews, retrieve saved local or GitHub PR fix prompts, and interpret CodeRabbit authentication and review output.
sickn33/agentic-awesome-skills
Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service.
luongnv89/claude-howto
Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.
codexstar69/bug-hunter
Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.
NVIDIA/NemoClaw
Find open issues that a NemoClaw PR may also fix or conflict with.
NVIDIA/NemoClaw
Run a NemoClaw daytime maintainer pass over release-targeted work.
NVIDIA/NemoClaw
Remove bracketed NemoClaw tags from GitHub issue and PR titles.
NVIDIA/NemoClaw
Audit and implement a NemoClaw dependency version upgrade, including Hermes and base images.
NVIDIA/NemoClaw
Continuously maintain automatic NemoClaw main E2E results through coordinated repairs.
NVIDIA/NemoClaw
Analyze retained NemoClaw CI timings for slow CLI tests, runner queues, or base-image publication.
Works with
Categories
Perform a requested security review of a NemoClaw PR or a PR linked to an issue. Nemoclaw Maintainer Security Code Review is an agent skill from NVIDIA/NemoClaw, published by the product's own GitHub organization. Perform a requested security review of a NemoClaw PR or a PR linked to an issue.
Nemoclaw Maintainer Security Code Review fits situations like: trust-boundary assessment; tasks that involve Code review; tasks that involve Security review.
Run `npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a claude-code`. Or copy the skill folder (.agents/skills/nemoclaw-maintainer-security-code-review in NVIDIA/NemoClaw) into .claude/skills/nemoclaw-maintainer-security-code-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a codex`. Or copy the skill folder (.agents/skills/nemoclaw-maintainer-security-code-review in NVIDIA/NemoClaw) into .agents/skills/nemoclaw-maintainer-security-code-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nemoclaw-maintainer-security-code-review, .gemini/skills/nemoclaw-maintainer-security-code-review, .github/skills/nemoclaw-maintainer-security-code-review and .opencode/skills/nemoclaw-maintainer-security-code-review in your project.
Going by SKILL.md and its folder, Nemoclaw Maintainer Security Code Review needs the command-line tools its instructions call (gh and git).
SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Nemoclaw Maintainer Security Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Nemoclaw Maintainer Security Code Review: Verdaccio Code Review (verdaccio/verdaccio, 18k stars), Requesting Code Review (HezaoHezao/poirot, 249 stars), Code Review (coderabbitai/skills, 187 stars) and Vibers Code Review (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/NemoClaw, which has 22,692 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 10, 2026.
Source: NVIDIA/NemoClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.