lecture-to-notes

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [SAFE]: No malicious obfuscation, persistence mechanisms, or unauthorized data exfiltration attempts were identified.
  • [COMMAND_EXECUTION]: The skill provides instructions for the user to configure the Clueso MCP connector using the command claude mcp add --transport http Clueso https://connect.clueso.io/mcp. This is a standard setup procedure for the Claude Code environment and targets a legitimate vendor endpoint.
  • [EXTERNAL_DOWNLOADS]: The instructions reference official documentation and setup URLs hosted on clueso.io. These are recognized as legitimate vendor-owned resources.
  • [PROMPT_INJECTION]: The skill processes transcription data from lecture recordings, creating a surface for potential indirect prompt injection.
  • Ingestion points: Lecture recordings and transcripts are ingested for analysis and summarization (SKILL.md).
  • Boundary markers: The workflow does not explicitly define delimiters or instructions to ignore embedded commands within the transcribed text.
  • Capability inventory: The skill utilizes Clueso MCP tools to write articles, capture video frames, and attach images to workspace projects.
  • Sanitization: No specific sanitization or filtering logic is described for the processed transcription content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:42 AM
Security Audit — agent-trust-hub — lecture-to-notes