youtube-summarizer
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of an external dependency from an unverified GitHub repository.
- Evidence: Instructions in
SKILL.mdandpackage.jsontogit clone https://github.com/kimtaeyoon83/mcp-server-youtube-transcript.git. - [REMOTE_CODE_EXECUTION]: The skill performs remote code execution by downloading and building an external package at runtime.
- Evidence:
git clone ... && npm install && npm run buildcommands provided in the installation workflow andpackage.json. - [COMMAND_EXECUTION]: The skill uses the shell to execute Node.js commands and platform-specific messaging tools.
- Evidence: Usage of
node --input-type=module -eto execute inline JavaScript andmessage --action sendto interact with Telegram. - [DYNAMIC_EXECUTION]: The skill generates and executes JavaScript code at runtime by interpolating video IDs into a shell command.
- Evidence: The inline script in
SKILL.mdthat importsgetSubtitlesand processes output usingnode -e. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from YouTube transcripts which could contain malicious instructions designed to influence the agent's summary or behavior.
- Ingestion points: Transcript data fetched via the
mcp-server-youtube-transcripttool. - Boundary markers: None identified in the prompt templates to delimit external transcript content from agent instructions.
- Capability inventory: File system writes to
/root/, shell command execution vianode, and network access via Telegram integration. - Sanitization: No evidence of sanitization for the transcript text before it is processed by the LLM.
- [DATA_EXFILTRATION]: The skill is configured to send transcript files to external platforms using environment-stored credentials.
- Evidence:
SKILL-OC.mdcontains instructions to usecurlto send documents to the Telegram Bot API using${TELEGRAM_BOT_TOKEN}.
Audit Metadata