feature-release-video
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill contains instructions for the user to manually configure the Clueso MCP connector using assistant-specific commands (e.g.,
claude mcp add). These are documented setup steps requiring user confirmation and are not executed automatically or hidden from the user. - [EXTERNAL_DOWNLOADS]: The skill references official vendor resources, including the MCP connection endpoint at
https://connect.clueso.io/mcpand documentation athttps://help.clueso.io. These URLs are consistent with the author's identity and the skill's stated purpose. - [PROMPT_INJECTION]: The skill processes untrusted input in the form of release notes and changelog text to generate scripts. While this presents a surface for indirect prompt injection, the risk is addressed by the workflow's requirement that the agent show the draft script to the user for review and approval before proceeding to video creation.
Audit Metadata