add-opening-hook
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an official Model Context Protocol (MCP) server at
https://connect.clueso.io/mcpand provides documentation links tohelp.clueso.io. These resources belong to the vendor's verified infrastructure. - [COMMAND_EXECUTION]: Provides instructions for the user to execute the command
claude mcp add --transport http Clueso https://connect.clueso.io/mcp. This is a documented, standard configuration step for adding the vendor's tools to the environment. - [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external video transcripts to generate narration and hooks.
- Ingestion points: Video transcripts and project data (Workflow Step 2).
- Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded instructions within the transcripts.
- Capability inventory: Video scene creation, trimming, and narration editing via the Clueso MCP.
- Sanitization: No specific sanitization or validation of transcript content is mentioned.
Audit Metadata