Official agent skill

Nemoclaw Maintainer Security Code Review

by NVIDIA in NVIDIA/NemoClaw

Perform a requested security review of a NemoClaw PR or a PR linked to an issue.

OfficialApache-2.0Auto-check passedDevelopment

Install Nemoclaw Maintainer Security Code Review

skills CLI
$ npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install NVIDIA/NemoClaw nemoclaw-maintainer-security-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/NVIDIA/NemoClaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nemoclaw-maintainer-security-code-review .claude/skills/nemoclaw-maintainer-security-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nemoclaw-maintainer-security-code-review
GitHub stars
23k
Token cost
~1.1k tokens
SKILL.md length
505 words
Files
1
Skills in repo
30
Repo updated
First seen
Licence
Apache-2.0

At a glance

Perform a requested security review of a NemoClaw PR or a PR linked to an issue.

  • Works in 6 steps: Parse the GitHub URL → Check Out the Code → Identify Changed Files → …
  • Trust-boundary assessment
  • SKILL.md covers Prerequisites, Step 1: Parse the GitHub URL, Step 2: Check Out the Code and Step 3: Identify Changed Files, plus 4 more sections
  • Calls gh and git; reaches github.com

What it does

Nemoclaw Maintainer Security Code Review is an agent skill from NVIDIA/NemoClaw, published by the product's own GitHub organization. Perform a requested security review of a NemoClaw PR or a PR linked to an issue. Use for vulnerability or trust-boundary assessment.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code review and Security review. It works with GitHub. The repository describes itself as: Run agents like Hermes, LangChain Deep Agents, and OpenClaw more securely inside NVIDIA OpenShell with managed inference. The licence is Apache-2.0.

When your agent uses it

  • Trust-boundary assessment
  • Tasks that involve Code review
  • Tasks that involve Security review

Example prompts

  • “/nemoclaw-maintainer-security-code-review”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Parse the GitHub URL
  2. Check Out the Code
  3. Identify Changed Files
  4. Read Each Changed File and Diff
  5. Analyze Against the Security Rubric
  6. Produce the Report

What it can do on your machine

Read from SKILL.md and the folder at commit fcbbab0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nemoclaw Maintainer Security Code Review loads about 1.1k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 505 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from NVIDIA/NemoClaw at commit fcbbab0, republished under its Apache-2.0 licence (© NVIDIA). 505 words, ~1,100 tokens.

Download SKILL.mdSave it as .claude/skills/nemoclaw-maintainer-security-code-review/SKILL.md (or your agent's skills folder).
name
nemoclaw-maintainer-security-code-review
description
Perform a requested security review of a NemoClaw PR or a PR linked to an issue. Use for vulnerability or trust-boundary assessment.
user_invocable
true
<!-- SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved. -->
<!-- SPDX-License-Identifier: Apache-2.0 -->

Security Code Review

Review the changes in a GitHub PR for security. An issue input must identify one open linked PR. Report a verdict for each category.

Prerequisites

  • gh (GitHub CLI) must be installed and authenticated.
  • git must be available.
  • Network access to clone repositories and fetch PR metadata.

Step 1: Parse the GitHub URL

If the user gives a PR or issue URL, extract the owner, repository, and number. Otherwise, ask for the URL.

Supported URL formats:

  • https://github.com/OWNER/REPO/pull/NUMBER
  • https://github.com/OWNER/REPO/issues/NUMBER

For a PR URL, verify the number before Step 2:

bash
gh pr view <number> --repo OWNER/REPO --json number,url

For an issue URL, list its open closing PRs:

bash
gh issue view <number> --repo OWNER/REPO --json closedByPullRequestsReferences \
  --jq '.closedByPullRequestsReferences | map(select(.state == "OPEN")) | .[].number'

Continue only when this returns one PR number, and verify that number with gh pr view. If it returns zero or more than one, stop and ask for the PR URL. Use the verified PR number in each later command.

Step 2: Check Out the Code

Compare gh repo view --json nameWithOwner -q .nameWithOwner with the URL. If the repositories match, check out the verified PR:

bash
gh pr checkout <number>

If the repositories do not match, clone the target to a temporary directory:

bash
REVIEW_DIR=$(mktemp -d)
gh repo clone OWNER/REPO "$REVIEW_DIR"
cd "$REVIEW_DIR"
gh pr checkout <number>

Step 3: Identify Changed Files

List all files changed from the base branch:

bash
git diff main...HEAD --name-status

If the PR targets another branch, use that branch as the base. Check it with:

bash
gh pr view <number> --json baseRefName -q .baseRefName

Step 4: Read Each Changed File and Diff

Read each changed file. Read its diff:

bash
git diff main...HEAD -- <file>

If a PR changes more than 30 files, review them in this order:

  1. Files that handle authentication, authorization, or credentials.
  2. Files that process user input (API handlers, CLI argument parsing, URL parsing).
  3. Configuration files (Dockerfiles, YAML policies, environment configs).
  4. New dependencies (package.json, requirements.txt, go.mod changes).
  5. Everything else.
Show full SKILL.md (232 more words)Show less

Step 5: Analyze Against the Security Rubric

Read the canonical Security Rubric. Independently evaluate the completed change against every category, including its trust-boundary questions and expected evidence. Do not rely on planning or implementation conclusions as review evidence.

For each of the nine categories, assign a verdict:

  • Use PASS when you find no issue. Give a short reason.
  • Use WARNING for a concern. Describe the risk and fix.
  • Use FAIL for a vulnerability. Describe its impact, severity, and fix.

Step 6: Produce the Report

Structure the output as follows:

Verdict

One paragraph summarizing the risk and whether the PR is safe to merge.

Findings Table

One row per finding:

#CategorySeverityFile:LineDescriptionRecommendation

If there are no findings, state that the review found none.

Detailed Analysis

For each category, give its PASS, WARNING, or FAIL verdict and reason.

Files Reviewed

List every file analyzed.

Important Notes

  • If the PR has no changed files, state that result and stop the review.
  • If no changed or reviewable security surface exists, state that result and stop the review.
  • Review security surfaces in drafts, including Dockerfiles, workflows, network policies, blueprints, dependencies, and security configuration.
  • For NemoClaw PRs, check SSRF bypasses, Dockerfile injection, network-policy bypasses, credential leaks, and blueprint changes.
  • Do not skip a category. If a category does not apply, mark it PASS and state why.
  • If severity is uncertain, use WARNING instead of PASS.

© NVIDIA, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/nemoclaw-maintainer-security-code-review of NVIDIA/NemoClaw.

Open the folder on GitHubat commit fcbbab0

Compare with similar skills

Nemoclaw Maintainer Security Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nemoclaw Maintainer Security Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nemoclaw Maintainer Security Code Review this skillNVIDIA/NemoClaw23k—~1.1kAutomated safety check: PassApache-2.0
Verdaccio Code Reviewverdaccio/verdaccio18k—~853Automated safety check: PassMIT
Requesting Code ReviewHezaoHezao/poirot2495 repos~1.6kAutomated safety check: PassMIT
Code Reviewcoderabbitai/skills187—~1.9kAutomated safety check: PassMIT
Vibers Code Reviewsickn33/agentic-awesome-skills47k2 repos~1.1kAutomated safety check: PassMIT
Code Review Specialistluongnv89/claude-howto42k—~764Automated safety check: PassMIT

Similar skills

  • Verdaccio Code Review

    verdaccio/verdaccio

    Reviews a verdaccio diff, branch or PR against the repository's review guide, verifies each finding in the code and reports only actionable issues.

    18k GitHub stars~853 tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Requesting Code Review

    HezaoHezao/poirot

    Pre-commit review: security scan, quality gates, auto-fix. An agent skill from HezaoHezao/poirot.

    249 GitHub starsUsed in 5 repos~1.6k tokens
    DevelopmentAuto-check passed
  • Code Review

    coderabbitai/skills

    Run CodeRabbit CLI reviews, retrieve saved local or GitHub PR fix prompts, and interpret CodeRabbit authentication and review output.

    187 GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Vibers Code Review

    sickn33/agentic-awesome-skills

    Human review workflow for AI-generated GitHub projects with spec-based feedback, security review, and follow-up PRs from the Vibers service.

    47k GitHub starsUsed in 2 repos~1.1k tokens
    SecurityAuto-check passed
  • Code Review Specialist

    luongnv89/claude-howto

    Reviews code for security, performance, quality and maintainability, using a checklist, a finding template and two metrics scripts.

    42k GitHub stars~764 tokensUpdated 10 days ago
    DevelopmentAuto-check passed
  • Bug Hunter

    codexstar69/bug-hunter

    Precision-first adversarial bug hunting for runtime, logic, data, concurrency, and security defects.

    520 GitHub stars~5k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from NVIDIA/NemoClaw

All 30 skills in this repo
  • Official

    Find open issues that a NemoClaw PR may also fix or conflict with.

    23k GitHub stars~893 tokensUpdated today
    Auto-check passed
  • Official

    Run a NemoClaw daytime maintainer pass over release-targeted work.

    23k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Audit and implement a NemoClaw dependency version upgrade, including Hermes and base images.

    23k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Official

    Continuously maintain automatic NemoClaw main E2E results through coordinated repairs.

    23k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Analyze retained NemoClaw CI timings for slow CLI tests, runner queues, or base-image publication.

    23k GitHub stars~644 tokensUpdated today
    Auto-check passed

Works with

Questions about Nemoclaw Maintainer Security Code Review

What does Nemoclaw Maintainer Security Code Review do?

Perform a requested security review of a NemoClaw PR or a PR linked to an issue. Nemoclaw Maintainer Security Code Review is an agent skill from NVIDIA/NemoClaw, published by the product's own GitHub organization. Perform a requested security review of a NemoClaw PR or a PR linked to an issue.

When should I use Nemoclaw Maintainer Security Code Review?

Nemoclaw Maintainer Security Code Review fits situations like: trust-boundary assessment; tasks that involve Code review; tasks that involve Security review.

How do I install Nemoclaw Maintainer Security Code Review in Claude Code?

Run `npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a claude-code`. Or copy the skill folder (.agents/skills/nemoclaw-maintainer-security-code-review in NVIDIA/NemoClaw) into .claude/skills/nemoclaw-maintainer-security-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Nemoclaw Maintainer Security Code Review in Codex?

Run `npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a codex`. Or copy the skill folder (.agents/skills/nemoclaw-maintainer-security-code-review in NVIDIA/NemoClaw) into .agents/skills/nemoclaw-maintainer-security-code-review in your project. Codex loads it when a task matches its description.

Can I use Nemoclaw Maintainer Security Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add NVIDIA/NemoClaw --skill nemoclaw-maintainer-security-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nemoclaw-maintainer-security-code-review, .gemini/skills/nemoclaw-maintainer-security-code-review, .github/skills/nemoclaw-maintainer-security-code-review and .opencode/skills/nemoclaw-maintainer-security-code-review in your project.

What does Nemoclaw Maintainer Security Code Review need to run?

Going by SKILL.md and its folder, Nemoclaw Maintainer Security Code Review needs the command-line tools its instructions call (gh and git).

Does Nemoclaw Maintainer Security Code Review access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Nemoclaw Maintainer Security Code Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nemoclaw Maintainer Security Code Review use?

Nemoclaw Maintainer Security Code Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nemoclaw Maintainer Security Code Review use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nemoclaw Maintainer Security Code Review?

Skills that share tags, products or a category with Nemoclaw Maintainer Security Code Review: Verdaccio Code Review (verdaccio/verdaccio, 18k stars), Requesting Code Review (HezaoHezao/poirot, 249 stars), Code Review (coderabbitai/skills, 187 stars) and Vibers Code Review (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nemoclaw Maintainer Security Code Review?

NVIDIA (a GitHub organization, an official publisher) maintains it in NVIDIA/NemoClaw, which has 22,692 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 10, 2026.

Source: NVIDIA/NemoClaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.