demo-by-vertical

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides the user with specific shell commands to install and configure the Clueso MCP server, such as claude mcp add --transport http Clueso https://connect.clueso.io/mcp.
  • [EXTERNAL_DOWNLOADS]: The skill references external endpoints and documentation on the vendor's domain (clueso.io), which are necessary for the setup and operation of the Clueso MCP.
  • [PROMPT_INJECTION]: The skill transcribes and analyzes external content (the 'base demo'), which presents a potential surface for indirect prompt injection.
  • Ingestion points: Transcribing and analyzing spoken audio from user-provided video files or existing projects (Step 2).
  • Boundary markers: None identified.
  • Capability inventory: Project duplication, script rewriting, narration audio generation, and project export.
  • Sanitization: The skill does not explicitly describe sanitization or validation of the transcribed text before it is used to generate new narration scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:42 AM
Security Audit — agent-trust-hub — demo-by-vertical