youtube

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses the Zapier:youtube_find_video tool, which is a well-known and legitimate service integration for searching public video metadata.
  • [SAFE]: No evidence of prompt injection, obfuscation, or data exfiltration was found. The instructions are focused on interpreting user intent and formatting search results.
  • [SAFE]: The skill does not request or use sensitive file system access, environment variables, or administrative privileges.
  • [SAFE]: No remote code execution or dynamic execution patterns were detected; the skill relies entirely on the model's reasoning and a single predefined tool.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it processes untrusted data (YouTube video titles and metadata).
  • Ingestion points: Data enters the context via the Zapier:youtube_find_video tool results in SKILL.md Step 3.
  • Boundary markers: None present; the agent is instructed to pool and evaluate all results directly.
  • Capability inventory: The skill has no capabilities for file-writing, network exfiltration (beyond the search tool), or command execution.
  • Sanitization: None present.
  • Note: The risk is assessed as safe/minimal because the skill lacks the exploitable tools required for an indirect injection to cause system harm.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 07:43 AM
Security Audit — agent-trust-hub — youtube