youtube-uploader
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts video titles, descriptions, and tags from agent context or user input and transmits them to the YouTube API. This presents a surface for indirect prompt injection if the agent generates these strings from untrusted external data (e.g., summarizing a malicious webpage). However, the risk is low as the data is treated as plain text parameters for an API call and not executed as local code.\n
- Ingestion points:
scripts/youtube-upload.tsprocesses CLI arguments for video metadata.\n - Boundary markers: Absent.\n
- Capability inventory: Network access via the trusted
googleapislibrary to perform video uploads (youtube.videos.insert) inscripts/youtube-upload.ts.\n - Sanitization: Absent; content is passed directly to the Google API.
Audit Metadata