youtube-channel-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The script communicates with api.browseract.com to initiate and retrieve results for YouTube data extraction workflows. This domain is an official resource for the vendor 'browser-act' and is necessary for the skill's primary functionality.
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a Python script (scripts/youtube_channel_api.py) to process user search queries and fetch channel information.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted content from YouTube channel data (names, descriptions, and handles).
  • Ingestion points: The run_youtube_channel_task function in scripts/youtube_channel_api.py retrieves data from the vendor API and prints it directly to the terminal.
  • Boundary markers: There are no explicit delimiters or warnings in the script's output to demarcate retrieved YouTube content from tool status messages.
  • Capability inventory: The skill uses requests for network communication and has standard local execution privileges for the Python environment.
  • Sanitization: The script does not apply specific filtering or sanitization to the text returned by the API before it is consumed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:52 AM
Security Audit — agent-trust-hub — youtube-channel-api-skill