skills/tellahq/skills/tella/Gen Agent Trust Hub

tella

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes video timelines, storyboards, and transcripts from external video projects, which represents an ingestion surface for untrusted data.
  • Ingestion points: Video metadata, transcripts, and timeline data are retrieved via the get_timeline and get_storyboard tools in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands within the processed data are specified in the instructions.
  • Capability inventory: The skill possesses write capabilities through tools like update_video and update_clip, allowing for the modification of video content based on processed data.
  • Sanitization: No specific sanitization or filtering logic for transcripts or user-provided media metadata is described.
  • [EXTERNAL_DOWNLOADS]: The documentation provides setup instructions using npx mcp-remote to connect to the remote Tella MCP server.
  • Evidence: The skill references npx mcp-remote https://api.tella.com/mcp as a connection method in SKILL.md.
  • Context: These instructions are provided for user-initiated configuration and target the official vendor domain (tella.com).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 04:34 PM
Security Audit — agent-trust-hub — tella