compliance-training-localization

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external MCP server at https://connect.clueso.io/mcp and documentation at https://help.clueso.io/mcp-setup. These resources are consistent with the vendor's infrastructure and are necessary for the skill's core functionality.
  • [COMMAND_EXECUTION]: Includes instructions for the assistant to guide users through executing the claude mcp add command to install the Clueso connector. This is a standard and transparent configuration step for utilizing the required MCP tools.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it processes external, potentially untrusted video content and scripts for translation and video production. 1. Ingestion points: User-provided compliance videos and scripts. 2. Boundary markers: None explicitly implemented to separate user data from instructions. 3. Capability inventory: Invokes Clueso MCP tools for narration generation, video syncing, rendering, and exporting. 4. Sanitization: No specific sanitization or filtering of input script content is described prior to processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:42 AM
Security Audit — agent-trust-hub — compliance-training-localization