youtube-transcript

Pass

Audited by Gen Agent Trust Hub on Mar 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) due to its core workflow of fetching and processing external transcript data.
  • Ingestion points: The script scripts/fetch-transcript.mjs fetches transcript text from YouTube URLs provided by users. This content is then saved to a file and read back into the agent's context.
  • Boundary markers: The prompt templates in SKILL.md (for translate and summarize actions) use simple --- delimiters to separate instructions from the transcript text. However, they lack explicit system-level instructions or rigid delimiters to prevent the agent from following instructions embedded within the transcript itself.
  • Capability inventory: The skill possesses file system write capabilities (creating directories and saving markdown files) and performs network requests to YouTube. While it does not execute the fetched text as code, the agent's interpretation of the text during summarization/translation could be manipulated by a malicious transcript.
  • Sanitization: The transcript text is normalized (whitespace removal) but is not sanitized for natural language instructions or adversarial content before being interpolated into the agent's prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 25, 2026, 06:30 PM
Security Audit — agent-trust-hub — youtube-transcript