youtube-api-skill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The script
scripts/youtube_api.pymakes network requests toapi.browseract.com. This is the official API endpoint for the skill's vendor, BrowserAct, and is used for its intended purpose of data extraction. - [COMMAND_EXECUTION]: The skill requires the agent to execute a Python script (
scripts/youtube_api.py) to manage the API workflow and retrieve results. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external YouTube pages via an intermediary API, creating a standard surface for indirect prompt injection.
- Ingestion points: External data enters the agent's context through the
result_stringvariable inscripts/youtube_api.pyafter fetching the task output. - Boundary markers: None identified; the raw output from the API is printed to the terminal for the agent to process.
- Capability inventory: The skill can execute local Python scripts and perform network operations to the vendor's API.
- Sanitization: There is no explicit sanitization or structural validation performed on the external content before it is displayed to the agent.
Audit Metadata