youtube-transcript-extractor-api-skill

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a bridge to external content (YouTube transcripts) which presents an Indirect Prompt Injection surface.
  • Ingestion points: The scripts/youtube_transcript_extractor_api.py script fetches video transcripts and metadata from the external BrowserAct API, which in turn scrapes content from YouTube.
  • Boundary markers: The script prints the extracted transcript and metadata directly to standard output without using delimiters or boundary markers to distinguish data from instructions for the agent.
  • Capability inventory: While the script itself only performs network requests and prints output, the agent executing the skill typically has access to broader capabilities such as file system operations and tool execution.
  • Sanitization: There is no evidence of sanitization or filtering of the transcript text to remove potential prompt injection payloads before it is passed to the agent.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to external services.
  • The script scripts/youtube_transcript_extractor_api.py communicates with api.browseract.com to initiate and poll for transcript extraction tasks. This domain is managed by the skill's vendor.
  • The skill uses the requests Python library to facilitate these connections.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 11:51 AM
Security Audit — agent-trust-hub — youtube-transcript-extractor-api-skill