webinar-to-highlight-clips

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the user to execute the command claude mcp add --transport http Clueso https://connect.clueso.io/mcp to install the necessary Model Context Protocol (MCP) server. This setup is a prerequisite for using the skill's features and points to the vendor's own infrastructure.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources hosted on clueso.io domains, including the MCP server endpoint and setup documentation. These are official vendor resources consistent with the skill's purpose.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection because it analyzes spoken audio and transcripts from user-provided recordings to find highlight candidates.
  • Ingestion points: Spoken audio and transcripts extracted from long-form recordings (SKILL.md, Workflow Step 2).
  • Boundary markers: Absent; there are no specific delimiters used to separate the transcript data from the agent's instructions during analysis.
  • Capability inventory: The skill utilizes Clueso tools to read project structures, split timelines, duplicate projects, and render video exports.
  • Sanitization: The instructions include a heuristic directive to "Never fabricate or embellish content that isn't actually in the transcript," but no technical sanitization or validation of the transcript content is performed before analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:42 AM
Security Audit — agent-trust-hub — webinar-to-highlight-clips