video-to-help-article

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to connect to the vendor's Model Context Protocol (MCP) server at https://connect.clueso.io/mcp. This is a legitimate configuration step for integrating the Clueso toolset with AI assistants like Claude or ChatGPT.
  • [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection due to its core function of processing external data.
  • Ingestion points: Raw screen recordings, Clueso project transcripts, and rendered video frames are ingested for analysis.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands within the transcripts are provided.
  • Capability inventory: The skill uses tools to watch videos, extract UI labels from frames, and generate markdown prose based on the transcript.
  • Sanitization: There are no explicit instructions for the agent to sanitize or filter the external transcript data before processing.
  • [SAFE]: The skill follows established practices for vendor-specific tool integration. All external references point to the vendor's own infrastructure (clueso.io), and the instructions are consistent with the skill's stated purpose of documentation generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:42 AM
Security Audit — agent-trust-hub — video-to-help-article