youtube-search-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes external content from YouTube search results, which could potentially contain adversarial instructions designed to influence the agent's behavior.
  • Ingestion points: Untrusted data (video titles, descriptions, and channel names) is fetched in scripts/youtube_search_api.py via the BrowserAct API response and printed to the agent's context.
  • Boundary markers: The skill does not use specific delimiters or include instructions for the agent to ignore potential commands embedded within the search results.
  • Capability inventory: The skill's potential impact is mitigated by its limited capabilities; the scripts do not perform local file writes, execute shell commands, or interact with non-vendor network endpoints.
  • Sanitization: The script outputs the raw metadata from YouTube without filtering or sanitizing the content for potential injection strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — youtube-search-api-skill