youtube-channel-api-skill
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The script communicates with
api.browseract.comto initiate and retrieve results for YouTube data extraction workflows. This domain is an official resource for the vendor 'browser-act' and is necessary for the skill's primary functionality. - [COMMAND_EXECUTION]: The skill instructs the agent to execute a Python script (
scripts/youtube_channel_api.py) to process user search queries and fetch channel information. - [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted content from YouTube channel data (names, descriptions, and handles).
- Ingestion points: The
run_youtube_channel_taskfunction inscripts/youtube_channel_api.pyretrieves data from the vendor API and prints it directly to the terminal. - Boundary markers: There are no explicit delimiters or warnings in the script's output to demarcate retrieved YouTube content from tool status messages.
- Capability inventory: The skill uses
requestsfor network communication and has standard local execution privileges for the Python environment. - Sanitization: The script does not apply specific filtering or sanitization to the text returned by the API before it is consumed by the agent.
Audit Metadata