polish-screen-demo

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for the agent to guide the user in running a command (claude mcp add) to integrate the Clueso MCP service. This is a standard procedure for enabling the external tools required for the skill's product demo workflow.
  • [EXTERNAL_DOWNLOADS]: The skill references an external Model Context Protocol (MCP) configuration URL (https://connect.clueso.io/mcp) belonging to the vendor. This is used to load the necessary editing tools into the assistant's environment.
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it processes external data from user-uploaded recordings and their associated audio transcripts.
  • Ingestion points: Screen recordings and audio transcripts analyzed in Workflow steps 1 and 2.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the processing logic for transcribed audio.
  • Capability inventory: The skill uses tools to split, trim, and export video files, and generate narration.
  • Sanitization: There are no documented steps for validating or sanitizing the content extracted from the audio transcripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:42 AM
Security Audit — agent-trust-hub — polish-screen-demo