youtube-summarizer

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of an external dependency from an unverified GitHub repository.
  • Evidence: Instructions in SKILL.md and package.json to git clone https://github.com/kimtaeyoon83/mcp-server-youtube-transcript.git.
  • [REMOTE_CODE_EXECUTION]: The skill performs remote code execution by downloading and building an external package at runtime.
  • Evidence: git clone ... && npm install && npm run build commands provided in the installation workflow and package.json.
  • [COMMAND_EXECUTION]: The skill uses the shell to execute Node.js commands and platform-specific messaging tools.
  • Evidence: Usage of node --input-type=module -e to execute inline JavaScript and message --action send to interact with Telegram.
  • [DYNAMIC_EXECUTION]: The skill generates and executes JavaScript code at runtime by interpolating video IDs into a shell command.
  • Evidence: The inline script in SKILL.md that imports getSubtitles and processes output using node -e.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from YouTube transcripts which could contain malicious instructions designed to influence the agent's summary or behavior.
  • Ingestion points: Transcript data fetched via the mcp-server-youtube-transcript tool.
  • Boundary markers: None identified in the prompt templates to delimit external transcript content from agent instructions.
  • Capability inventory: File system writes to /root/, shell command execution via node, and network access via Telegram integration.
  • Sanitization: No evidence of sanitization for the transcript text before it is processed by the LLM.
  • [DATA_EXFILTRATION]: The skill is configured to send transcript files to external platforms using environment-stored credentials.
  • Evidence: SKILL-OC.md contains instructions to use curl to send documents to the Telegram Bot API using ${TELEGRAM_BOT_TOKEN}.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 04:35 AM
Security Audit — agent-trust-hub — youtube-summarizer