lecture-to-notes
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: No malicious obfuscation, persistence mechanisms, or unauthorized data exfiltration attempts were identified.
- [COMMAND_EXECUTION]: The skill provides instructions for the user to configure the Clueso MCP connector using the command
claude mcp add --transport http Clueso https://connect.clueso.io/mcp. This is a standard setup procedure for the Claude Code environment and targets a legitimate vendor endpoint. - [EXTERNAL_DOWNLOADS]: The instructions reference official documentation and setup URLs hosted on
clueso.io. These are recognized as legitimate vendor-owned resources. - [PROMPT_INJECTION]: The skill processes transcription data from lecture recordings, creating a surface for potential indirect prompt injection.
- Ingestion points: Lecture recordings and transcripts are ingested for analysis and summarization (SKILL.md).
- Boundary markers: The workflow does not explicitly define delimiters or instructions to ignore embedded commands within the transcribed text.
- Capability inventory: The skill utilizes Clueso MCP tools to write articles, capture video frames, and attach images to workspace projects.
- Sanitization: No specific sanitization or filtering logic is described for the processed transcription content.
Audit Metadata