youtube-extract

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from YouTube video descriptions and instructions the agent to 'clone' repositories or 'WebFetch' links found within that data.
  • Ingestion points: yt-dlp --dump-json extracts the video description, which is then parsed by a Python one-liner to find URLs.
  • Boundary markers: There are no specific boundary markers or instructions to the agent to ignore prompt-injection attempts within the video description or the content of the cloned repositories.
  • Capability inventory: The skill possesses the ability to execute shell commands (yt-dlp, ffmpeg), fetch web content, and clone Git repositories.
  • Sanitization: There is no sanitization of the description text before the agent interacts with the URLs contained within it.
  • [COMMAND_EXECUTION]: The skill uses shell interpolation for the $URL variable and timestamp variables (HH:MM:SS) in multiple yt-dlp and ffmpeg calls. While typically managed by the agent's environment, this pattern presents a surface for command injection if the input URL is maliciously crafted.
  • [REMOTE_CODE_EXECUTION]: Step 5 instructs the agent to clone repositories found in video descriptions. If the agent proceeds to analyze or run code within these repositories to answer questions, it could lead to the execution of malicious code from an untrusted source.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 01:02 AM
Security Audit — agent-trust-hub — youtube-extract