feature-release-video

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains instructions for the user to manually configure the Clueso MCP connector using assistant-specific commands (e.g., claude mcp add). These are documented setup steps requiring user confirmation and are not executed automatically or hidden from the user.
  • [EXTERNAL_DOWNLOADS]: The skill references official vendor resources, including the MCP connection endpoint at https://connect.clueso.io/mcp and documentation at https://help.clueso.io. These URLs are consistent with the author's identity and the skill's stated purpose.
  • [PROMPT_INJECTION]: The skill processes untrusted input in the form of release notes and changelog text to generate scripts. While this presents a surface for indirect prompt injection, the risk is addressed by the workflow's requirement that the agent show the draft script to the user for review and approval before proceeding to video creation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:42 AM
Security Audit — agent-trust-hub — feature-release-video