mrbeast-perspective

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The shell script scripts/fetch_youtube_subtitles.sh installs the yt-dlp package from the official Python Package Index (PyPI). yt-dlp is a standard and well-known open-source tool for YouTube data extraction. Use of such well-known technology tools from official registries is considered safe.- [COMMAND_EXECUTION]: The skill executes local Python and shell scripts (analyze_titles.py, retention_curve_checker.py, thumbnail_audit.py, and fetch_youtube_subtitles.sh) to perform content auditing. These scripts are invoked via command-line arguments to process user-provided text or images.- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests and processes untrusted data. \n
  • Ingestion points: Untrusted data enters the agent context through user-provided video titles and script files processed by the analysis tools. \n
  • Boundary markers: The agent is instructed to provide a one-time disclaimer and includes specific 'EXIT TRIGGER' keywords to revert to its standard assistant persona. \n
  • Capability inventory: The skill uses WebSearch and executes internal scripts for data analysis. \n
  • Sanitization: The included scripts use regular expressions and character analysis to extract metrics; they do not perform dynamic evaluation of the content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 10:11 AM
Security Audit — agent-trust-hub — mrbeast-perspective