mrbeast-perspective
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell and Python scripts for content analysis.
fetch_youtube_subtitles.sh: Downloads YouTube subtitles usingyt-dlp. It installsyt-dlpviapipif not found. While it executes shell commands, it is a legitimate tool within the stated purpose of analyzing video content.analyze_titles.py,retention_curve_checker.py,thumbnail_audit.py: These are pure text-processing scripts for analyzing video metadata and scripts. They perform no network operations or sensitive file access.- [REMOTE_CODE_EXECUTION]: The README mentions
npx skills add alchaincyf/mrbeast-skill. This uses the officialvercel-labs/skillsinstaller, which is a recognized service for managing agent skills. The installation command is standard for this ecosystem. - [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths, or unauthorized network exfiltration patterns were detected in the instructions or scripts.
- [PROMPT_INJECTION]: The skill uses a role-play prompt to adopt the 'MrBeast' persona. It includes clear 'EXIT TRIGGER' phrases ('退出', '切回正常') to allow the user to escape the persona, which is a safety best practice. It does not attempt to bypass underlying AI safety guardrails.
Audit Metadata