youtube-seo

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes ffmpeg for converting video files to audio and executes a local script (transcribe.sh) for transcription. These commands are necessary for the skill's media processing tasks and are implemented as standard workflows.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external video transcripts, which are untrusted inputs that could potentially contain instructions to influence agent output.
  • Ingestion points: transcript text and video/audio files provided by the user in the SKILL.md workflow.
  • Boundary markers: There are no explicit delimiters or specific instructions for the agent to treat transcript content as data rather than instructions.
  • Capability inventory: Shell command execution (ffmpeg) and local script execution.
  • Sanitization: No sanitization of the transcript content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 07:29 AM
Security Audit — agent-trust-hub — youtube-seo