add-opening-hook

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an official Model Context Protocol (MCP) server at https://connect.clueso.io/mcp and provides documentation links to help.clueso.io. These resources belong to the vendor's verified infrastructure.
  • [COMMAND_EXECUTION]: Provides instructions for the user to execute the command claude mcp add --transport http Clueso https://connect.clueso.io/mcp. This is a documented, standard configuration step for adding the vendor's tools to the environment.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection by processing external video transcripts to generate narration and hooks.
  • Ingestion points: Video transcripts and project data (Workflow Step 2).
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded instructions within the transcripts.
  • Capability inventory: Video scene creation, trimming, and narration editing via the Clueso MCP.
  • Sanitization: No specific sanitization or validation of transcript content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:42 AM
Security Audit — agent-trust-hub — add-opening-hook