youtube-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The script scripts/youtube_api.py makes network requests to api.browseract.com. This is the official API endpoint for the skill's vendor, BrowserAct, and is used for its intended purpose of data extraction.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute a Python script (scripts/youtube_api.py) to manage the API workflow and retrieve results.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external YouTube pages via an intermediary API, creating a standard surface for indirect prompt injection.
  • Ingestion points: External data enters the agent's context through the result_string variable in scripts/youtube_api.py after fetching the task output.
  • Boundary markers: None identified; the raw output from the API is printed to the terminal for the agent to process.
  • Capability inventory: The skill can execute local Python scripts and perform network operations to the vendor's API.
  • Sanitization: There is no explicit sanitization or structural validation performed on the external content before it is displayed to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — youtube-api-skill