polish-screen-demo
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for the agent to guide the user in running a command (
claude mcp add) to integrate the Clueso MCP service. This is a standard procedure for enabling the external tools required for the skill's product demo workflow. - [EXTERNAL_DOWNLOADS]: The skill references an external Model Context Protocol (MCP) configuration URL (
https://connect.clueso.io/mcp) belonging to the vendor. This is used to load the necessary editing tools into the assistant's environment. - [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it processes external data from user-uploaded recordings and their associated audio transcripts.
- Ingestion points: Screen recordings and audio transcripts analyzed in Workflow steps 1 and 2.
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the processing logic for transcribed audio.
- Capability inventory: The skill uses tools to split, trim, and export video files, and generate narration.
- Sanitization: There are no documented steps for validating or sanitizing the content extracted from the audio transcripts.
Audit Metadata