webinar-to-highlight-clips
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the user to execute the command
claude mcp add --transport http Clueso https://connect.clueso.io/mcpto install the necessary Model Context Protocol (MCP) server. This setup is a prerequisite for using the skill's features and points to the vendor's own infrastructure. - [EXTERNAL_DOWNLOADS]: The skill references several external resources hosted on
clueso.iodomains, including the MCP server endpoint and setup documentation. These are official vendor resources consistent with the skill's purpose. - [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection because it analyzes spoken audio and transcripts from user-provided recordings to find highlight candidates.
- Ingestion points: Spoken audio and transcripts extracted from long-form recordings (SKILL.md, Workflow Step 2).
- Boundary markers: Absent; there are no specific delimiters used to separate the transcript data from the agent's instructions during analysis.
- Capability inventory: The skill utilizes Clueso tools to read project structures, split timelines, duplicate projects, and render video exports.
- Sanitization: The instructions include a heuristic directive to "Never fabricate or embellish content that isn't actually in the transcript," but no technical sanitization or validation of the transcript content is performed before analysis.
Audit Metadata