explain-it-simply

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external Model Context Protocol (MCP) server at 'https://connect.clueso.io/mcp' and provides documentation links to 'help.clueso.io'. These are official resources belonging to the vendor (clueso-ai).
  • [COMMAND_EXECUTION]: Instructions are included to run the command 'claude mcp add --transport http Clueso https://connect.clueso.io/mcp' to install the required tool for video processing. This is a standard setup procedure for the Clueso platform.
  • [DATA_EXPOSURE]: The skill includes instructions to retrieve brand colors and guidelines from the user's workspace to ensure visual consistency in generated videos.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided topics, questions, and visual assets to generate content.
  • Ingestion points: User-supplied topics, questions, diagrams, and screenshots (SKILL.md).
  • Boundary markers: None specified for user input isolation.
  • Capability inventory: Calls to external Clueso tools for video generation, narration, and rendering (SKILL.md).
  • Sanitization: No explicit sanitization of user-provided text before script generation is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:42 AM
Security Audit — agent-trust-hub — explain-it-simply