youtube-comments-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes YouTube comments, which are untrusted external data sources that could contain malicious instructions intended to manipulate the agent's behavior.
  • Ingestion points: External data enters the agent context through the result_string returned by the run_youtube_comments_task function in scripts/youtube_comments_api.py.
  • Boundary markers: The skill lacks explicit delimiters or warnings to the agent to ignore potentially malicious instructions embedded within the extracted YouTube comment text.
  • Capability inventory: The skill has the capability to perform network operations (communicating with the BrowserAct API) and access the BROWSERACT_API_KEY from the environment.
  • Sanitization: There is no evidence of sanitization, filtering, or escaping applied to the comment_text field before it is presented to the agent for analysis or summarization.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — youtube-comments-api-skill