youtube-downloader

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/download_video.py executes the yt-dlp and ffmpeg binaries to facilitate video downloads and processing. These commands are invoked using the subprocess module with argument lists (shell=False), which correctly avoids shell execution and prevents command injection vulnerabilities.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes content from arbitrary external URLs, creating a surface for indirect prompt injection.\n
  • Ingestion points: The script fetches video metadata, such as titles and descriptions, from external websites via yt-dlp in scripts/download_video.py.\n
  • Boundary markers: There are no explicit instructions or delimiters in the documentation to prevent the AI agent from potentially following instructions embedded within the downloaded metadata if it is instructed to read those files later.\n
  • Capability inventory: The skill has the ability to write files to the local system and execute subprocesses.\n
  • Sanitization: The script implements a sanitize_filename function to ensure that potentially malicious metadata does not lead to directory traversal or illegal file creation.\n- [EXTERNAL_DOWNLOADS]: The skill instructions in SKILL.md guide the user to install the yt-dlp package from PyPI. yt-dlp is a well-known and widely used open-source tool for video downloading.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:14 AM
Security Audit — agent-trust-hub — youtube-downloader