youtube-scriptwriting
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists entirely of instructional documentation and a script template. It does not contain any scripts (Python, JavaScript, Shell), binaries, or configuration files that would enable automated actions or tool execution.
- [SAFE]: A thorough review of all Markdown files found no evidence of prompt injection, data exfiltration attempts, or obfuscated content. The instructions are focused solely on creative writing and video production techniques.
- [INDIRECT_PROMPT_INJECTION]: The research workflow described in
references/research.mdsuggests that users feed competitor transcripts into an AI model for analysis. While this is a data ingestion surface, the skill itself lacks any tools or executable capabilities that could be exploited via malicious content embedded in those transcripts. The analysis identifies this as a safe instructional pattern. - Ingestion points: Suggestions in
references/research.mdto ingest external transcripts from YouTube videos. - Boundary markers: Not specified in the instructional text.
- Capability inventory: None. The skill does not define or use any tools or scripts.
- Sanitization: Not applicable as no code processes the data.
Audit Metadata